Certificates must be added to vCenter trust root (vCenter 7.0 U2 and above).

The following certificates must be added to the vCenter trust root to validate the certificate used to sign the OVA:

  • This is an example of an OVA deployed without certificates:

  • This is an example of an OVA deployed with certificates:

To add the necessary certificates:

  • From the vSphere client, go to Menu > Administration > Certificate Management > Trusted root certificates and add each certificate.
    • Browse the certificate location and select the certificate.
    • Select the checkbox to enable Start Root certificate push to vCenter Hosts.
    • Click the Add button.

Note: Perform this step for each of the three required certificates.