PowerFlex 4.8: How to Enable Stringent Certificate Feature

Summary: Many users have CA policies that prohibit IP addresses in the Certificate Subject Alternative Name (SAN) and only Fully Qualified Domain Names (FQDNs) are allowed. The lack of IP addresses in the certificate conflicts with PowerFlex Manager logic when it comes to the zipper or yum repositories that we use. PowerFlex 4.8 has a new feature to support stringent rules for certificates. This is a new security mode within package manager. Now, when creating a custom certificate or the Powerflex appliance certificate, the customer can choose between Standard and Stringent modes. The Standard Mode does not require DNS, but includes IPs and FQDNs, and the Stringent mode in which PowerFlex Manager converts the ingress IPS to FQDNs and then builds the repo URLs. ...

Acest articol se aplică pentru Acest articol nu se aplică pentru Acest articol nu este legat de un produs specific. Acest articol nu acoperă toate versiunile de produs existente.

Instructions

  1. Access PowerFlex Manager UI> Settings> Security> Appliance  SSL Cetificate
  2. Select the option Generate Certificate Signing Request (CSR)

In the Appliance SSL Certificate, the Security Mode line shows if a customer is already using Stringent or Standard mode.

Appliance SSL Certificate 

  1. On the pop up, choose Stringent as the Security Level

Stringent" as the Security Level

  1. Add the DNS Hostname details:

 

Note: It is always recommended to include one DNS per entry; however, if this is not possible, the Management DNS can be used for the Data entries as well. If there are physically isolated OOB networks, a DNS entry on the OOB network is required to resolve the FQDN to the OOB ingress IP.

 

Note: Once the CSR is generated, do not deviate from what is in the Subject Alternative Name (SAN) Section; otherwise, the system shows an error when trying to upload the signed certificate in the Upload SSL certificate section.

 

CSR generated

  1. Upload the signed certificate. See article Powerflex 4.X: How to Sign and Upload a Chain of SSL Certificates to PFMP
  2. You can review the DNS hostnames associated with the certificate:

Review DNS hostnames associated with the certificate:  

Produse afectate

PowerFlex rack, ScaleIO
Proprietăți articol
Article Number: 000479321
Article Type: How To
Ultima modificare: 31 Jul 2026
Version:  2
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.