メイン コンテンツに進む
  • すばやく簡単にご注文が可能
  • 注文内容の表示、配送状況をトラック
  • 会員限定の特典や割引のご利用
  • 製品リストの作成とアクセスが可能
  • 「Company Administration(会社情報の管理)」では、お使いのDell EMCのサイトや製品、製品レベルでのコンタクト先に関する情報を管理できます。

Updating Dell VxRail with Custom Certificates (Customer Correctable)

概要: Step-by-step guidance to replace with customer certificates for Dell VxRail environments. vSphere provides security by using certificates to encrypt communications, authenticate services, and sign tokens. ...

この記事は次に適用されます:   この記事は次には適用されません: 

手順

vSphere uses certificates to:

  • Encrypt communications between two nodes, such as vCenter Server and an ESXi host.
  • Authenticate vSphere services.
  • Perform internal actions such as signing tokens.

vSphere's internal certificate authority, VMware Certificate Authority (VMCA), provides all the certificates necessary for vCenter Server and ESXi. VMCA is installed on every Platform Services Controller, immediately securing the solution without any other modification. Keeping this default configuration provides the lowest operational overhead for certificate management. vSphere provides a mechanism to renew these certificates in the event they expire.

vSphere also provides a mechanism to replace certain certificates with your own certificates. However, it is advised to replace only the SSL certificate that provides encryption between nodes, to keep your certificate management overhead low.

Custom Certificate Integration

The vSphere environment is flexible to give the customers the opportunity to work with custom SSL certificates, as their company policies sometimes mandate that. The following steps walk you through changing certificates for various components in a VxRail environment.

  1. Replacing VxRail Manager's self-signed certificate
    • This procedure is accessible on the SolVe online portal. Go to 'How To' Procedures > 'How To' Change other VxRail Cluster settings > Choose your current VxRail Manager version > Replace the VxRail Manager SSL Certificate, then generate the procedure. If you do not have access to that portal, contact Dell support. For guidance on creating the Certificate Signing Request and modifying the received cert files, see KB article VxRail: How to apply for a new certificate for VxRail Manager.
  2. Replacing vCenter Server certificates using a Custom Certificate Authority (CA) Signed Certificate
  3. Manually reestablishing trust between VxRail Manager and vCenter Server after custom certificate integration
  4. Replacing ESXi host SSL certificates
  5. Replacing vRealize Log Insight certificates
Note: Generating Certificate Signing Requests (CSRs) using third-party tools or signing them using the internal company's CA is not supported by Dell support.

If you face any issues during certificate replacement, reach out to Dell support for assistance.

その他の情報

対象製品

VxRail, VxRail Appliance Family
文書のプロパティ
文書番号: 000019755
文書の種類: How To
最終更新: 27 4月 2024
バージョン:  10
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。
文書のプロパティ
文書番号: 000019755
文書の種類: How To
最終更新: 27 4月 2024
バージョン:  10
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。