PowerFlex: How to Add SSL Trusted Certificates
Summary: You can upload a trusted SSL certificate from a certificate authority (CA). You can use a trusted SSL certificate to establish a secure LDAP connection to Active Directory.
Instructions
Adding SSL trusted certificates
Before you upload a trusted SSL certificate, you must obtain the certificate file. The file must contain an X.509 certificate in PEM format.
It must start with ---BEGIN CERTIFICATE--- and end with ---END CERTIFICATE---.
Steps
- On the menu bar, click Settings and then click Security.
- Click SSL Trusted Certificates. The SSL Trusted Certificates page opens.
- Click Add.
- Click Choose File and select the SSL certificate.
- Provide a Name for the certificate. The name must be a single word.
- To upload the certificate, click Save.
Adding appliance SSL certificates
About this task
Uploading an SSL certificate for the appliance ensures secure transmission by encrypting data that PowerFlex Manager sends over the web. It also provides authentication and ensures that data is routed to its intended endpoint and prevents users from receiving browser security errors.
To upload an SSL certificate, you typically perform the steps in the process:
Steps
-
Generate a certificate signing request (CSR) from the PowerFlex Manager user interface. Generating a CSR using a third-party certificate tool is unsupported.
-
Download the CSR.
-
Submit the CSR to a certificate authority (CA). The CA provides a valid SSL certificate.
-
Upload the SSL certificate to PowerFlex Manager.
Generating a certificate signing request
A certificate signing request (CSR) includes information (such as domain name, locale) that certificate authorities require to provide a valid SSL certificate. After generating the CSR, download the encrypted text, and then submit it to a certificate authority. The certificate authority provides a valid SSL certificate for you to upload.
Steps
-
On the menu bar, click Settings and then click Security.
-
Click Appliance SSL Certificates.
The Appliance SSL Certificates page opens.
-
Click Generate Certificate Signing Request.
- In the Distinguished Name (www.domain.com) box, enter a distinguished name in the format
www.domain.com (for example, dellpowerflex.com). - In the Business Name box, enter a business name where the certificate is recorded.
- In the Department Name box, enter a department name of the organizational unit (for example, IT, HR, or Sales) for which the certificate is generated.
- In the Locality (Town/City) box, enter a locality name in which the organization is located.
- In the State (Province/Region) box, enter a state name in which the organization is located (do not abbreviate).
- From the Country list, select a country in which the organization is located.
- In the Email box, enter a valid email address.
- Click Generate.
- In the Distinguished Name (www.domain.com) box, enter a distinguished name in the format
-
Click Download Certificate Signing Request, and then copy the text that is displayed. To receive a valid SSL certificate, submit this text to a certificate authority.
Downloading the certificate signing request
After generating the certificate signing request (CSR), download the resulting text and submit it to a certificate authority. The certificate authority provides an SSL certificate for you to upload to PowerFlex Manager.
- On the menu bar, click Settings and then Security.
- Click Appliance SSL Certificates.
The Appliance SSL Certificates page opens.
- Click Download Certificate Signing Request.
- To receive a valid SSL certificate, copy the displayed text and then submit it to a certificate authority.
Uploading an SSL certificate
--BEGIN CERTIFICATE--- and end with ---END CERTIFICATE---.
- On the menu bar, click Settings and then click Security.
- Click Appliance SSL Certificates.
The Appliance SSL Certificates page opens.
- Click Choose File under SSL Certificate and select an SSL certificate.
- Click Choose File under Trusted CA Certificate and select an SSL certificate.
- To upload the certificate, click Save.
Adding resource credentials
PowerFlex Manager requires a root-level username and password to access and manage nodes, switches, VMware vCenter, element managers, PowerFlex gateway, and operating system resources.
- Name—A user-defined name that identifies the credentials.
- Type—A type of resource that uses the credential.
- Resources—The total number of resources to which the credential is assigned.
- Name of the user who created and modified the credential.
- Date and time that the credential was created and last modified.
- Create credentials
- Edit existing credentials
- Delete existing credentials
Additional Information
Related product documents:
- PowerFlex 4.5.x and PowerFlex Manager 4.6.x Adding SSL trusted certificates
- PowerFlex Manager 4.8.x Adding SSL trusted certificates Page 199
- PowerFlex Manager 5.0.x Adding SSL trusted certificates Page 138
Related articles:
- PowerFlex: Gateway SSL Certificate Expires Every 90 Days Causing the CSI Driver to Fail.
- PowerFlex 4.X: Kubernetes Ingress Controller Fake Certificate
- PowerFlex: SSL Certificate Verify Failed - Failed to Bootstrap
- PowerFlex: How to Use OpenSSL to Generate a CSR and Add the SSL Certificate
- Powerflex 4.X: How to Sign and Upload a Chain of SSL Certificates to PFMP
- PowerFlex 4.8: How to Enable Stringent Certificate Feature