Mr.PlanB Logo

    Newsletter

    Subscribe our newsletter

    Get new infrastructure guides, comparison reports, and migration notes in your inbox.

    Infrastructure notes, guides, and new tools. Unsubscribe anytime.

    Back to Blog
    VMware
    vCenter
    Certificates
    Security

    vCenter Expired Certificate Not Shown in Certificate Management

    February 18, 2026
    4 min read

    Say you're getting this alert in vCenter, and the certificate seems to be nowhere:

    Certificate “OU=mID-…, CN=data-encipherment” from “data-encipherment” expires on 2023-09-22 But it’s not visible in Certificate Management, and everything there shows as valid

    That's actually a big clue. This is almost certainly not one of the standard Machine SSL or Solution User certificates you manage in the UI. It's a VMware internal data-encipherment certificate stored inside VECS (VMware Endpoint Certificate Store).

    That's why you don't see it in any of these places, because it lives somewhere else:

    • Administration → Certificate Management
    • Machine SSL
    • Solution Users

    What "data-encipherment" usually means

    In vCenter, that CN is typically associated with one of these:

    • vSphere VM encryption
    • vSAN encryption
    • KMS integration
    • Internal encryption services
    • vCenter internal trust components

    These certs are often automatically generated, not user-facing, and stored in VECS stores like DATA_ENCIPHERMENT. Sometimes they expire and get replaced, but the old one lingers and triggers alarms, which is classic vCenter behavior.

    Step 1: SSH into the VCSA

    ssh root@your-vcenter
    

    Then enable Bash:

    shell
    

    Step 2: List all VECS stores

    /usr/lib/vmware-vmafd/bin/vecs-cli store list
    

    In the output, you're looking for store names something like:

    • MACHINE_SSL_CERT
    • TRUSTED_ROOTS
    • data-encipherment
    • DATA_ENCIPHERMENT

    If you see a store named data-encipherment or similar, that's your target.

    Step 3: List certificates in that store

    For example, this lists every entry in that store with its details:

    /usr/lib/vmware-vmafd/bin/vecs-cli entry list --store DATA_ENCIPHERMENT --text
    

    That should show the alias, the Not After date, and the subject for each entry. Find the expired one matching:

    CN=data-encipherment
    

    Step 4: Remove the expired certificate

    If it's clearly expired and not the active one:

    /usr/lib/vmware-vmafd/bin/vecs-cli entry delete --store DATA_ENCIPHERMENT --alias <alias_name>
    

    Be careful here. Do NOT delete the currently valid cert; only delete the expired duplicate.

    Step 5: Restart certificate services

    After cleanup, restart the certificate services:

    service-control --restart vmcad
    service-control --restart vpxd
    

    Or, if you prefer, restart all of the services at once:

    service-control --stop --all
    service-control --start --all
    

    Why it doesn't show in the UI

    The Certificate Management UI only shows Machine SSL, Solution Users, and Trusted Roots. It does NOT show internal encryption stores, some legacy stores, or certain VECS entries. That's why the certificate feels invisible.

    Important: before deleting

    If you are using vSphere VM Encryption, vSAN Encryption, or an external KMS, double-check with:

    /usr/lib/vmware-vmafd/bin/vecs-cli entry list --store DATA_ENCIPHERMENT --text
    

    Make sure a newer valid cert is present and that you are not deleting the only cert in that store. If you only see one expired cert and no replacement, you may need to regenerate it instead of deleting it.

    If you want to be extra safe

    Take a VECS backup first so you have a record of the store:

    mkdir /root/vecs_backup
    /usr/lib/vmware-vmafd/bin/vecs-cli entry list --store DATA_ENCIPHERMENT --text > /root/vecs_backup/data_enc.txt
    

    You could even snapshot the VCSA before making any of these changes.

    The 90% likely scenario

    Here is what usually happened:

    1. vCenter auto-renewed the encryption cert
    2. The old one expired
    3. The expired entry didn't auto-clean
    4. The alarm stuck around

    Removing the expired entry from the store clears the alert in vCenter.