Integrated Dell Remote Access Controller 9 Version User's Guide

Network security

While accessing the iDRAC Web interface, a security warning is displayed stating that the SSL certificate issued by the Certificate Authority (CA) is not trusted.

iDRAC includes a default iDRAC server certificate to ensure network security while accessing through the Web-based interface and remote RACADM. This certificate is not issued by a trusted CA. To resolve this, upload a iDRAC server certificate issued by a trusted CA (for example, Microsoft Certificate Authority, Thawte or Verisign).

Why the DNS server not registering iDRAC?

Some DNS servers register iDRAC names that contain only up to 31 characters.

When accessing the iDRAC Web-based interface, a security warning is displayed stating that the SSL certificate hostname does not match the iDRAC hostname.

iDRAC includes a default iDRAC server certificate to ensure network security while accessing through the Web-based interface and remote RACADM. When this certificate is used, the web browser displays a security warning because the default certificate that is issued to iDRAC does not match the iDRAC hostname (for example, the IP address).

To resolve this, upload an iDRAC server certificate issued to the IP address or the iDRAC hostname. When generating the CSR (used for issuing the certificate), ensure that the common name (CN) of the CSR matches the iDRAC IP address (if certificate issued to IP) or the registered DNS iDRAC name (if certificate is issued to iDRAC registered name).

To make sure that the CSR matches the registered DNS iDRAC name:
  1. In iDRAC Web interface, go to Overview > iDRAC Settings > Network. The Network page is displayed.
  2. In the Common Settings section:
    • Select the Register iDRAC on DNS option.
    • In the DNS iDRAC Name field, enter the iDRAC name.
  3. Click Apply.

Why am I unable to access iDRAC from my web browser?

This issue may occur if HTTP Strict Transport Security (HSTS) is enabled. HSTS is a web security mechanism which allows web browsers to interact using only the secure HTTPS protocol, and not HTTP.

Enable HTTPS on your browser and login to iDRAC to resolve the issue.

Why am I unable to complete operations that involve a remote CIFS share?

Import/export or any other remote file share operations that involve a CIFS share fail if they use only SMBv1. Ensure that the SMBv2 protocol is enabled on the server providing SMB/CIFS share. Refer to the Operating System documentation on how to enable the SMBv2 protocol.

