2V0-621 · Question #14
An administrator would like to use the VMware Certificate Authority (VMCA) as an Intermediate Certificate Authority (CA). The first two steps performed are: - Replace the Root Certificate - Replace…
The correct answer is A. Replace Solution User Certificates (Intermediate CA) C. Replace the VMware Directory Service Certificate. When deploying VMCA as an Intermediate CA, after replacing the Root and Machine SSL certificates, the next required steps are replacing Solution User Certificates and the VMware Directory Service Certificate using the correct procedure variants.
Question
An administrator would like to use the VMware Certificate Authority (VMCA) as an Intermediate Certificate Authority (CA). The first two steps performed are:
- Replace the Root Certificate
- Replace Machine Certificates (Intermediate CA)
Which two steps would need to be performed next? (Choose two.)
Options
- AReplace Solution User Certificates (Intermediate CA)
- BReplace the VMware Directory Service Certificate (Intermediate CA)
- CReplace the VMware Directory Service Certificate
- DReplace Solution User Certificates
How the community answered
(58 responses)- A67% (39)
- B10% (6)
- D22% (13)
Why each option
When deploying VMCA as an Intermediate CA, after replacing the Root and Machine SSL certificates, the next required steps are replacing Solution User Certificates and the VMware Directory Service Certificate using the correct procedure variants.
Replacing Solution User Certificates via the Intermediate CA procedure is the next required step after Machine SSL replacement, because solution users authenticate internally to vCenter using certificates that must chain back to the enterprise-signed VMCA root. Using the correct '(Intermediate CA)' variant ensures these certificates are issued with the proper intermediate chain.
This option incorrectly labels the VMware Directory Service certificate replacement with an '(Intermediate CA)' qualifier that does not match the documented procedure, making it the wrong process variant to select.
The VMware Directory Service (vmdird) uses its own certificate for SSO domain replication and authentication, and this certificate must be replaced as part of the full Intermediate CA rollout to ensure all internal vSphere services trust the updated certificate hierarchy.
Replacing Solution User Certificates without the '(Intermediate CA)' qualifier uses the standard replacement procedure rather than the Intermediate CA workflow, which would not properly chain certificates back to the enterprise-signed root.
Concept tested: VMCA as Intermediate CA certificate replacement workflow
Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.authentication.doc/GUID-5C1A72C8-98F2-4C41-B58F-0E4CF2CF9FB1.html
Topics
Community Discussion
No community discussion yet for this question.