I am sure you would have read this many times. Incase if you missed by any chance, ensure both points are considered.
- The new certificates already exist and you know the location of the new certificates. For increased security, generate each certificate and private key on the machine where it will be used. The new SSL certificate for each vSphere component must have a unique base DN.
- Updating the vCenter Server Certificate may fail with an error if multiple service IDs exist for the lookup service
When updating the certificate for vCenter Server using the SSL Certificate Automation Tool, the step may fail with the error:The certificates that's provided as input may not be a unique certificate
This may be caused byvpxd
having multiple service IDs for the Lookup service in thevpxd.cfg
file.