The system administrator can replace a self-signed certificate with a trusted one from a certificate authority. You can use Subject Alternative Name (SAN) certificates, wildcard certificates, or any other method of multi-use certification appropriate for your environment as long as you satisfy the trust requirements.


Navigate to the vCloud Automation Center Appliance management console by using its fully qualified domain name,


Log in with user name root and the password you specified when deploying the Identity Appliance.


Navigate to vCAC Settings > SSL.


Click SSL.


Select the certificate type from the Choose Action menu. If you are using a PEM encoded certificate, for example for a distributed environment, select Import PEM encoded certificate.

Certificates that you import must be trusted and must also be applicable to all instances of vCloud Automation Center Appliance and any load balancer by using Subject Alternative Name (SAN) certificates.



Import a certificate


Copy the certificate values from BEGIN PRIVATE KEY to END PRIVATE KEY, including the header and footer, and paste them in the RSA Private Key text box.


Copy the certificate values from BEGIN CERTIFICATE to END CERTIFICATE, including the header and footer, and paste them in the Certificate Chain text box.


(Optional) If your certificate has one, copy the pass phrase that encrypts the private key of the certificate that you are importing, and paste it in the Pass Phrase text box.

Generate a self-signed certificate


Type a common name for the certificate in the Common Name text box. You can use the fully qualified domain name of the virtual appliance ( or a wild card, such as * If you use a load balancer, you need to specify the FQDN of the load balancer or a wildcard that matches the name of the load balancer. Do not accept a default value if one is shown, unless it matches the host name of the virtual appliance.


Type your organization name, such as your company name, in the Organization text box.


Type your organizational unit, such as your department name or location, in the Organizational Unit text box.


Type a two-letter ISO 3166 country code, such as US, in the Country text box.


Click Replace Certificate.

After a few minutes, the certificate details appear on the page.

The certificate is updated.