vCenter VCSA will have default self-sign certificate which communicate with 443 over https. There are three method of certificate 1. Self-Sign Certificate 2. Custom certificate 3. VMCA We are discussing with vCenter replaced certificate either custom and VMCA. I am using custom method. Mostly organization will have their CA server locally or outsourced or public CA server service. Embedded vCenter you need to replace certificate on one appliance, incase of external vCenter you need to replace on PSC and vCenter. Before replacing and after replacing certificate you can check SSL certificate details with this command “openssl s_client -connect localhost:443” This is article we going to secure LDAP on VSCA. The LDAP(Secure) on PSC Identity Source Configuration Wizard. vCenter LDAP is integrated on PSC. If its embedded vCenter you can perform this Steps on vCenter. If vCenter is external, you need to perform this step on PSC not on vCenter. Befo