Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.3.0.0 CLI Administration Guide

Certificate management

You can manage TLS certificates using the OneFS command line interface.

The isi certificate settings view command enables viewing all of the certificate-related configuration options. For example:

# isi certificate settings view
Certificate Monitor Enabled: Yes
Certificate Pre Expiration Threshold: 4W2D
Default HTTPS Certificate
ID: default
Subject: C=US, ST=Washington, L=Bellingham, O="Sample Systems, Inc.", OU=Sample Systems, CN=Sample Systems, emailAddress=support@samplesys.com
Status: valid

The configuration options Certificate monitor enabled and Certificate Pre Expiration Threshold control a nightly cron job that monitors the expiration of every managed certificate and raises a CELOG alert when a certificate is set to expire within the configured threshold. The default expiration is 30 days. The ID: default option indicates that this certificate is the default TLS certificate.

The isi certificate server list command lists the available certificates. For example:
# isi certificate server list
ID      Name    Status  Expires
-------------------------------------------
a50e6da default valid   2021-12-25T11:01:55
c392083 mycert  valid   2020-04-19T09:40:29
-------------------------------------------
Total: 2
You can view the settings for a particular certificate using the isi certificate server view <certificate_name> command, where <certificate_name> is the name of the certificate for which to view settings. For example, suppose that you want to view the settings for a certificate named mycert:
# isi certificate server view mycert
          ID: c39208312f11f9d85a383f1fb4338e3eac92258c066d01931684a4c2bf343f71
        Name: mycert
Description:
     Subject: C=US, ST=Washington, CN=*.local.samplesys.com, emailAddress=admincritter@samplesys.com
      Issuer: C=US, ST=Washington, L=Bellingham, CN=AdminCritter Root, emailAddress=AdminCritter@samplesys.com
      Status: valid
  Not Before: 2019-04-10T09:40:29
   Not After: 2020-04-19T09:40:29
Fingerprints
            Type: SHA1
           Value: 58:e7:8e:1f:1a:bb:5f:15:94:88:6b:91:be:e1:4f:47:76:ac:df:90
 
            Type: SHA256
           Value: c3:92:08:31:2f:11:f9:d8:5a:38:3f:1f:b4:33:8e:3e:ac:92:25:8c:06:6d:01:93:16:84:a4:c2:bf:34:3f:71
   DNS Names: *.local.samplesys.com

Note the DNS Names listed when you view the certificate information. OneFS attempts to map any configured SmartConnect names or aliases to one of the certificates available to the system. If no match is found, OneFS uses the default certificate.

You can change the certificate settings using the isi certificate settings modify command. For example, to change the default HTTPS certificate to the mycert certificate:
# isi certificate settings modify --default-https-certificate=mycert
To verify that the default certificate has been changed:
# isi certificate settings view
Certificate Monitor Enabled: Yes
Certificate Pre Expiration Threshold: 4W2D
Default HTTPS Certificate
ID: mycert
Subject: C=US, ST=Washington, CN=*.local.samplesys.com, emailAddress=admincritter@samplesys.com
                                  Status: valid

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\