Encryption and security certificates
ESXi and vCenter Server are well supported with standard X.509 version 3 certificates (you can get more details on these certificates at https://tools.ietf.org/html/rfc6187 ) to encrypt session data between components. By default, VMware Certificate Authority (VMCA) provisions vCenter Server components and ESXi hosts with signed certificates.
VMware virtual infrastructure use the following certificates by default:
- ESXi certificates: Used for SSL communication to and from the ESXi host. VMware CA delivers these certificates by default, and they are stored locally on each ESXi host.
- Machine SSL certificates: Used for communicating to and from vCenter Servers and Platform Service Controller instances. All communication goes through the reverse proxy, then a single certificate can be used. VMware CA provisions these certificates and they are stored in the VMware Endpoint Certificate Store (VECS).
- Solution user certificates: Used by all solutions and services...