<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Certificate on Matt Allford</title><link>https://www.mattallford.com/tags/certificate/</link><description>Recent content in Certificate on Matt Allford</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sat, 02 Apr 2016 10:45:08 +0000</lastBuildDate><atom:link href="https://www.mattallford.com/tags/certificate/index.xml" rel="self" type="application/rss+xml"/><item><title>vSphere 6 - Reconfigure Embedded vCenter to External PSC</title><link>https://www.mattallford.com/vsphere-6-reconfigure-embedded-vcenter-to-external-psc/</link><pubDate>Sat, 02 Apr 2016 10:45:08 +0000</pubDate><guid>https://www.mattallford.com/vsphere-6-reconfigure-embedded-vcenter-to-external-psc/</guid><description>&lt;h1 id="introduction"&gt;Introduction&lt;/h1&gt;
&lt;p&gt;As of vSphere 6.0U1, VMware allow an embedded vCenter server deployment to be reconfigured to an external deployment, which demotes the Platform Services Controller (PSC) components of the embedded node and points the VC server to an external PSC node which resides in the same Single Sign On (SSO) domain as the source embedded node.&lt;/p&gt;
&lt;p&gt;This is done by using the utility &lt;strong&gt;cmsso-util&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Before we get too much further, there are two main uses for cmsso-util:&lt;/p&gt;</description></item><item><title>Exchange 2013 Hybrid Mail 'Pending' - RootCAType Certificate Issues</title><link>https://www.mattallford.com/exchange-2013-hybrid-mail-pending-rootcatype-certificate-issues/</link><pubDate>Thu, 18 Feb 2016 21:40:27 +0000</pubDate><guid>https://www.mattallford.com/exchange-2013-hybrid-mail-pending-rootcatype-certificate-issues/</guid><description>&lt;p&gt;I manage an Exchange 2013 deployment at work which is configured in Hybrid with Office365. Recently we had to change our SSL certificate that was being used for both TLS for the hybrid connection and also for our client facing DNS names. Due to changes with our 3rd party SSL certificate provider, this was a new SSL certificate installation rather than a renewal.&lt;/p&gt;
&lt;p&gt;I generated the certificate and installed it onto all of the Exchange servers on-premises and during our change window, made the changes to bind the services to the new certificate and then ran the Hybrid connection wizard to update the certificate used in our On-Prem send connector to Office365 and also to the receive connector in our Office365 tenant. I&amp;rsquo;d confirmed the change was OK and sent some test emails back and forth over the hybrid connection, all looked good.&lt;/p&gt;</description></item><item><title>VMWare Update Manager sysimage.fault.SSLCertificateError</title><link>https://www.mattallford.com/vmware-update-manager-sysimage-fault-sslcertificateerror/</link><pubDate>Mon, 11 Jan 2016 01:37:53 +0000</pubDate><guid>https://www.mattallford.com/vmware-update-manager-sysimage-fault-sslcertificateerror/</guid><description>&lt;p&gt;Recently I&amp;rsquo;ve gone through the process of replacing the machine_ssl certificates on our vCenter and PSC nodes at work, and shortly after I went to use Update Manager and received the following error: sysimage.fault.SSLCertificateError&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.mattallford.com/wp-content/uploads/2016/01/VUM_1.png"&gt;&lt;img alt="VUM_1" loading="lazy" src="https://www.mattallford.com/wp-content/uploads/2016/01/VUM_1-300x87.png"&gt;
&lt;/a&gt;
We opted for the &amp;lsquo;Hybrid&amp;rsquo; model of certificates in vSphere 6, where the machine_ssl certificate on the PSC and VC server nodes is replaced with an externally signed certificate, and the VMCA takes care of all of the solution user certificates using the default configuration.&lt;/p&gt;</description></item></channel></rss>