PowerFlex 4.8: How to Enable Stringent Certificate Feature

摘要: Many users have CA policies that prohibit IP addresses in the Certificate Subject Alternative Name (SAN) and only Fully Qualified Domain Names (FQDNs) are allowed. The lack of IP addresses in the certificate conflicts with PowerFlex Manager logic when it comes to the zipper or yum repositories that we use. PowerFlex 4.8 has a new feature to support stringent rules for certificates. This is a new security mode within package manager. Now, when creating a custom certificate or the Powerflex appliance certificate, the customer can choose between Standard and Stringent modes. The Standard Mode does not require DNS, but includes IPs and FQDNs, and the Stringent mode in which PowerFlex Manager converts the ingress IPS to FQDNs and then builds the repo URLs. ...

本文章適用於 本文章不適用於 本文無關於任何特定產品。 本文未識別所有產品版本。

說明

  1. Access PowerFlex Manager UI> Settings> Security> Appliance  SSL Cetificate
  2. Select the option Generate Certificate Signing Request (CSR)

In the Appliance SSL Certificate, the Security Mode line shows if a customer is already using Stringent or Standard mode.

Appliance SSL Certificate 

  1. On the pop up, choose Stringent as the Security Level

Stringent" as the Security Level

  1. Add the DNS Hostname details:

 

Note: It is always recommended to include one DNS per entry; however, if this is not possible, the Management DNS can be used for the Data entries as well. If there are physically isolated OOB networks, a DNS entry on the OOB network is required to resolve the FQDN to the OOB ingress IP.

 

Note: Once the CSR is generated, do not deviate from what is in the Subject Alternative Name (SAN) Section; otherwise, the system shows an error when trying to upload the signed certificate in the Upload SSL certificate section.

 

CSR generated

  1. Upload the signed certificate. See article Powerflex 4.X: How to Sign and Upload a Chain of SSL Certificates to PFMP
  2. You can review the DNS hostnames associated with the certificate:

Review DNS hostnames associated with the certificate:  

受影響的產品

PowerFlex rack, ScaleIO
文章屬性
文章編號: 000479321
文章類型: How To
上次修改時間: 31 7月 2026
版本:  2
向其他 Dell 使用者尋求您問題的答案
支援服務
檢查您的裝置是否在支援服務的涵蓋範圍內。