Replacing the VMware Identity Manager (vIDM)…

Replacing the VMware Identity Manager (vIDM)…

Overview: Why and When to Replace the vIDM Certificate VMware Identity Manager (vIDM), also known as Workspace ONE Access, uses an SSL certificate to secure its web interface and establish trust with integrated VMware products (like vRealize/Aria Automation and Operations). Replacing this […]


Broadcom Social Media Advocacy

VMUG Connect 2025 – Minimal VMware Cloud…

VMUG Connect 2025 – Minimal VMware Cloud…

I had a great time attending the inaugural VMUG Connect 2025 in St. Louis this past April. Like many others, the event was a great way to connect and share our passion for VMware technologies with both new and familiar faces from our community. Here are a few great write-ups from attendees of […]


Broadcom Social Media Advocacy

Installing and Using the vCert Tool

vCert is a powerful certificate management utility developed for VMware Cloud Foundation environments. It allows administrators to inspect, manage, and replace certificates across the vCenter Server infrastructure with minimal effort. This article walks you through the installation and usage of the vCert v6.0.0 tool.


🔧 Installation

To begin, download the vCert tool archive provided in the related article and upload it to your vCenter Server appliance. Once uploaded, execute the following commands to extract and run the tool:

# unzip -q vCert-6.0.0-20250218.zip
# cd vCert-6.0.0-20250218
# chmod +x vCert
# ./vCert.py

Running the Script

To display help options:

# ./vCert.py --help

Arguments available:

  • --env ENVIRONMENT: Load environment config file
  • --run OPERATION: Execute operation without menu
  • --user USER: Provide SSO administrator username
  • --password PASSWORD: Provide corresponding password

Once launched interactively, you’ll see a menu:

VCF Certificate Management Utility (version 6.0.0)
-----------------------------------------------------------------
1. Check current certificate status
2. View certificate info
3. Manage certificates
4. Manage SSL trust anchors
5. Check configurations
6. Reset all certificates with VMCA-signed certificates
7. ESXi certificate operations
8. Restart services
9. Generate certificate report
E. Exit

🗂 Logs and Files

  • Logs: /var/log/vmware/vCert/vCert.log
  • Temp/Backup files: /root/vCert-master/YYYYMMDD

Temporary files (except backups) are deleted on exit.


🧪 Menu Options Overview

1️⃣ Check Current Certificate Status

Performs a comprehensive health check:

  • Expiry validation
  • SAN (Subject Alternative Name) presence
  • Key usage compliance
  • CA validity and signature algorithm checks
  • Solution User to Service Principal consistency

2️⃣ View Certificate Info

Displays readable info for:

  • Machine SSL and Solution User certs
  • CA certs (VECS & VMware Directory)
  • STS, SMS, Smart Card, and LDAPS certs

3️⃣ Manage Certificates

Replace or modify certificates for:

  • Machine SSL
  • Solution Users
  • STS Signing
  • Smart Card CA
  • LDAPS Identity Source
  • VECS and VMware Directory CA stores
  • vCenter Extensions & SMS

Supports PEM/DER, PKCS#7, and PKCS#12 formats.

💡 Certificate chains must be complete when importing custom CA-signed certificates.

4️⃣ Manage SSL Trust Anchors

  • Validate trust anchors used by Lookup Services
  • Update anchors across SSO domain nodes

5️⃣ Check Configurations

Includes:

  • SSL interception detection
  • STS store alignment (e.g., legacy vs. MACHINE_SSL_CERT)
  • VECS store health and permission checks

6️⃣ Reset All Certificates

Resets:

  • Machine SSL
  • Solution User
  • STS signing
    …all signed by the VMCA.

7️⃣ ESXi Certificate Operations

Manage ESXi host certificates:

  • Validate trust alignment between vCenter and ESXi
  • Check DB consistency
  • Replace host certificates (rui.crt, rui.key, castore.pem)

🔁 Requires host service restart & vCenter re-connection.

8️⃣ Restart Services

Options:

  • Restart all VMware services
  • Restart specific service by name

9️⃣ Generate Certificate Report

Outputs a detailed report covering:

  • VECS entries
  • Service Principals
  • STS entries
  • Smart Card and LDAP certs
  • Lookup Service SSL anchors

Saved under: /var/log/vmware/vCert

📌 Summary

The vCert 6.0.0 tool is an essential utility for environments where certificate lifecycle management is critical. Whether you’re replacing a Machine SSL cert, troubleshooting expired STS tokens, or ensuring trust between vCenter and ESXi hosts, vCert provides a safe and guided workflow.

Remember: always use with caution and ensure full system backups are in place before making change

Link for use Manage Certificates menu to check and replace the certificates.

vCenter Server Identity Federation with Zitadel

vCenter Server Identity Federation with Zitadel

Not sure when it happened, but I have been binging self-hosted identity providers like Netflix shows, this season features Authentik, KeyCloak, Synology SSO and Pocket ID. To add to my collection, I was recently asked whether Zitadel could also work as an identity provider with vCenter Server […]


Broadcom Social Media Advocacy

Supported chipsets for the USB Network Native…

Supported chipsets for the USB Network Native…

A longtime community favorite, the USB Network Native Driver for ESXi Fling makes it super easy for users to expand additional networking capabilities for ESXi-x86. While helping a customer recently, I realized that we did not have a published list of supported USB Network adaptors (VID/DID) […]


Broadcom Social Media Advocacy

🚀 Registration Is Now Open: Explore 2025 in Las Vegas

I’ve always attended VMware Explore in Barcelona—an event that’s consistently been a highlight of my year. But 2025 might be my first time experiencing VMware Explore in Las Vegas, and I couldn’t be more excited!

🌍 Why I Love VMware Explore

Explore is more than just a tech conference—it’s about the VMware community. This vibrant network of professionals, enthusiasts, and leaders is the heartbeat of the event.

At Explore in Barcelona, I had the honor of meeting Hock Tan, CEO of Broadcom, and connecting with incredible leaders like Corey Romero (#vExpert lead) and Josef Zach, our Czech #VMUG leader.

One of the best parts? Meeting the people you usually only see in online training sessions. It was amazing to talk in person with Tim Burkard and witness his brilliant session on Demystifying Distributed Security in VMware Cloud Foundation—a real magician at work!

🔍 What To Expect at Explore 2025

I’m looking forward to updates around VMware Cloud Foundation (VCF) 9, especially sessions with experts like:

  • Duncan Epping on vSAN innovations
  • Frank Denneman covering the latest on AI and Private AI Foundation

The technical depth at Explore is always unmatched, and this year’s focus on Private AI and enhanced cloud solutions will be one to watch.

🎓 Learning, Certifications, and Hands-on Labs

Explore is your playground for practical learning. You’ll have the opportunity to dive deep into Hands-on Labs and even get certified. From personal experience, I highly recommend aiming for the:

  • VCP-VCF Administrator certification
  • VCP-VCF Architect certification

As Socrates said: “I know that I know nothing.” There’s always something new to learn—and VMware Explore is the perfect place to do it.

🎉 Don’t Miss the Explore Party!

No Explore experience is complete without the legendary Explore Party! Which band will play this year? That’s still under wraps, but it’s always unforgettable.

💰 Pricing Overview

Take advantage of early-bird pricing until June 16:

  • Full Event Pass – $1,795 (save $200 early)
  • Essentials Pass – $1,195
  • Meetings+ Pass – $695

➡️ Register here: VMware Explore Las Vegas Event Page

🌎 Can’t Make It to Vegas? Join VMware Explore On Tour

If you can’t attend in person, VMware Explore On Tour is coming to cities worldwide! These 1–1.5 day events feature top sessions, Hands-on Labs, and networking opportunities.

Explore On Tour 2025 Stops:

  • Mumbai – September 16–17
  • London – September 17–18
  • Paris – October 15–16
  • Sydney – October 22
  • Tokyo – October 29
  • Frankfurt – November 12–13

More info: VMware Explore Blog
Watch past sessions: Explore Video Library
Check the FAQ: Explore Las Vegas FAQs


💬 Will I see you in Vegas this year?
Let’s connect, learn, and celebrate everything that makes the VMware community so powerful.

👉 Register now for VMware Explore 2025 in Las Vegas

If you need help getting approval to attend, try using the convince your manager letter.

Integrating VMware NSX with Ubiquiti UniFi via…

Integrating VMware NSX with Ubiquiti UniFi via…

In my homelab environment — which I often refer to as my personal Solution Center — I run a full stack of VMware Cloud Foundation (VCF), where NSX is a core component for network virtualization. One of the key challenges I’ve faced was how to properly connect NSX’s Application Virtual Networks […]


Broadcom Social Media Advocacy