In some cases, you need to upload certificates from the command line.

The vCloud Connector Server and vCloud Connector Node Admin Web consoles support uploading only a single root, intermediate, and signed certificate. To upload multiple root or intermediate certificates, use the command line interface.

Also use the command line interface if you need to upload fewer than three certificates as the UI requires you to upload all three certificates. Some Certificate Authorities only issue two certificates.

Certificates must be in the X.509 format.

You must import certificates in the following order: root certificate, intermediate certificate, then signed certificate.


If you obtain certificates from a Windows Server 2008 Certificate Authority, ensure that you select the Subordinate Certificate Authority template type while requesting the certificate.

You have obtained the certificates and have copied them to a directory in the vCloud Connector Server or Node.


Log on to the console of the vCloud Connector Server or vCloud Connector Node as admin.

The default password is vmware.


If the certificates that you obtained from your Certificate Authority are not in the X.509 format, convert them to the X.509 format.

openssl pkcs7 -in <path/../certificate.cer> -print_certs | openssl x509 > <path/../certificate.cer>


If the certificate is already in the X.509 format, you might get an error.


At the prompt, change directory:

cd /usr/local/tcserver/vfabric-tc-server-standard/server_or_agent/conf


Import the root certificate.

/usr/java/default/bin/keytool -import -trustcacerts -alias root -file <location of root .cer file> -keystore tcserver.jks -storepass changeme


Import intermediate certificates. Ensure that you import multiple intermediate certificates in an order of signing chain.

/usr/java/default/bin/keytool -import -trustcacerts -alias intermediate -file <location of intermediate .cer file> -keystore tcserver.jks -storepass changeme


You must provide a unique alias name for every intermediate certificate you upload.


Import the signed certificate.

/usr/java/default/bin/keytool -import -trustcacerts -alias hcserver_or_hcagent -file <location of .cer file> -keystore tcserver.jks -storepass changeme


Enable SSL.


Go to the Server or Node Admin Web console at https://<vCCServerOrNode_IPaddress>:5480.


Log on as admin.

The default password is vmware.


For the Server, click the Server tab, then the SSL tab. For the Node, click the Node tab, then the SSL tab.


Click Enable SSL.


You can ignore the following message: "vCloud Connector server hostname does not match CN in SSL certificate."

After you install valid certificates, you must do the following.

Deselect the Ignore SSL Certificate flag for each Node for which you installed a valid certificate and update the Node's registration with the vCloud Connector Server.


Go to the vCloud Connector Server Admin Web console at https://<vCCServer_IPaddress>:5480.


Log on as admin. The default password is vmware.


Click the Nodes tab.


Click the gears icon next to the Node and select Edit.


Deselect Ignore SSL Certificate, then click Update.

See also Register vCloud Connector Nodes with vCloud Connector Server.

Restart the vCloud Connector Server after uploading new certificates for the change to take effect.