

If you do want to replace the certificates, see the VMware Knowledge Base system. In almost all cases, it is not necessary to replace the existing certificates. The virtual machine's default configuration includes one certificate for authenticating requests to modify the secure boot configuration, including the secure boot revocation list, from inside the virtual machine, which is a Microsoft KEK (Key Exchange Key) certificate. A VMware certificate that is used only for booting ESXi inside a virtual machine.

