vCenter Expired Certificate Not Shown in Certificate Management
Say you're getting this alert in vCenter, and the certificate seems to be nowhere:
Certificate “OU=mID-…, CN=data-encipherment” from “data-encipherment” expires on 2023-09-22 But it’s not visible in Certificate Management, and everything there shows as valid
That's actually a big clue. This is almost certainly not one of the standard Machine SSL or Solution User certificates you manage in the UI. It's a VMware internal data-encipherment certificate stored inside VECS (VMware Endpoint Certificate Store).
That's why you don't see it in any of these places, because it lives somewhere else:
- Administration → Certificate Management
- Machine SSL
- Solution Users
What "data-encipherment" usually means
In vCenter, that CN is typically associated with one of these:
- vSphere VM encryption
- vSAN encryption
- KMS integration
- Internal encryption services
- vCenter internal trust components
These certs are often automatically generated, not user-facing, and stored in VECS stores like DATA_ENCIPHERMENT. Sometimes they expire and get replaced, but the old one lingers and triggers alarms, which is classic vCenter behavior.
Step 1: SSH into the VCSA
ssh root@your-vcenter
Then enable Bash:
shell
Step 2: List all VECS stores
/usr/lib/vmware-vmafd/bin/vecs-cli store list
In the output, you're looking for store names something like:
- MACHINE_SSL_CERT
- TRUSTED_ROOTS
- data-encipherment
- DATA_ENCIPHERMENT
If you see a store named data-encipherment or similar, that's your target.
Step 3: List certificates in that store
For example, this lists every entry in that store with its details:
/usr/lib/vmware-vmafd/bin/vecs-cli entry list --store DATA_ENCIPHERMENT --text
That should show the alias, the Not After date, and the subject for each entry. Find the expired one matching:
CN=data-encipherment
Step 4: Remove the expired certificate
If it's clearly expired and not the active one:
/usr/lib/vmware-vmafd/bin/vecs-cli entry delete --store DATA_ENCIPHERMENT --alias <alias_name>
Be careful here. Do NOT delete the currently valid cert; only delete the expired duplicate.
Step 5: Restart certificate services
After cleanup, restart the certificate services:
service-control --restart vmcad
service-control --restart vpxd
Or, if you prefer, restart all of the services at once:
service-control --stop --all
service-control --start --all
Why it doesn't show in the UI
The Certificate Management UI only shows Machine SSL, Solution Users, and Trusted Roots. It does NOT show internal encryption stores, some legacy stores, or certain VECS entries. That's why the certificate feels invisible.
Important: before deleting
If you are using vSphere VM Encryption, vSAN Encryption, or an external KMS, double-check with:
/usr/lib/vmware-vmafd/bin/vecs-cli entry list --store DATA_ENCIPHERMENT --text
Make sure a newer valid cert is present and that you are not deleting the only cert in that store. If you only see one expired cert and no replacement, you may need to regenerate it instead of deleting it.
If you want to be extra safe
Take a VECS backup first so you have a record of the store:
mkdir /root/vecs_backup
/usr/lib/vmware-vmafd/bin/vecs-cli entry list --store DATA_ENCIPHERMENT --text > /root/vecs_backup/data_enc.txt
You could even snapshot the VCSA before making any of these changes.
The 90% likely scenario
Here is what usually happened:
- vCenter auto-renewed the encryption cert
- The old one expired
- The expired entry didn't auto-clean
- The alarm stuck around
Removing the expired entry from the store clears the alert in vCenter.