2V0-621 · Question #28
Which two statements are correct regarding vSphere certificates? (Choose two.)
The correct answer is B. ESXi host upgrades preserve the existing SSL certificate. C. ESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) during. In vSphere, ESXi hosts receive SSL certificates from VMCA when added to vCenter, and those certificates are retained - not replaced - when the host is upgraded.
Question
Which two statements are correct regarding vSphere certificates? (Choose two.)
Options
- AESXi host upgrades do not preserve the SSL certificate and reissue one from the VMware
- BESXi host upgrades preserve the existing SSL certificate.
- CESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) during
- DESXi hosts have self-signed SSL certificates by default.
How the community answered
(22 responses)- A5% (1)
- B91% (20)
- D5% (1)
Why each option
In vSphere, ESXi hosts receive SSL certificates from VMCA when added to vCenter, and those certificates are retained - not replaced - when the host is upgraded.
This statement is incorrect - ESXi host upgrades preserve the existing certificate rather than reissuing a new one from VMCA, maintaining continuity of secure management connections.
ESXi host upgrades preserve the existing SSL certificate rather than issuing a new one, ensuring that trust relationships, certificate pinning, and management connectivity are not disrupted by the upgrade process. This behavior prevents the need for re-trust operations across vCenter and any external tools that have pinned the host certificate after an upgrade.
When an ESXi host is provisioned or added to a vCenter Server environment, VMCA automatically generates and assigns a signed SSL certificate to the host as part of the default certificate management workflow introduced in vSphere 6.0. This replaces the older model of purely self-signed certificates and centralizes certificate authority management under VMCA.
ESXi hosts managed by a vCenter Server receive VMCA-signed certificates by default rather than purely self-signed certificates, which was the pre-vSphere 6.0 behavior before VMCA was introduced.
Concept tested: vSphere VMCA certificate assignment and upgrade certificate preservation
Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.authentication.doc/GUID-AFEFB75D-7E55-4791-9CC0-E36A10CC8773.html
Topics
Community Discussion
No community discussion yet for this question.