Summary
Security Token Service (STS) signing certificates can expire as soon as two years from the initial deployment
1
, and if expired, it can cause users to be unable to log in to vSphere Client or the vmware-vpxd service to fail to start.
1
To prevent this, it is recommended to replace the STS certificate if the expiration date is in less than 6 months.
2
To replace the certificate, users can run the fixst script to regenerate the certificates.
3
Additionally, users can try browser workarounds to access vCenter via the Flex client.
3
According to