Skip to main content
NetApp Knowledge Base

How to generate and convert a signed certificate for Active IQ Unified Manager

Views:
4,001
Visibility:
Public
Votes:
1
Category:
oncommand-unified-manager
Specialty:
om
Last Updated:

Applies to

  • Active IQ Unified Manager 9.x ( AIQ UM )
  • OnCommand Unified Manager 6.x ( UM )
  • OnCommand Unified Manager 7.x ( UM )
  • OnCommand Unified Manager 9.x ( UM )

Description

This guide documents the process to generate and install a CA signed certificate into ActiveIQ Unified Manager, and how to resolve common errors encountered during this process.

Things to be aware of:

  • The certificate may be signed and downloaded in several formats from the CA server; however, ActiveIQ Unified Manager expects the signed certificate to be in the .pem format. The .pem certificate must be base64 encoded. Renaming a .cer certificate to a .pem certificate will not work.
  • Some signing authorities may not include the root certificate or the server certificate when the chain is downloaded. AIQ UM expects the chain to include the server certificate, one or more intermediate certificates, and the root certificate.
  • The order the certificates are placed within the chain is important. Unified Manager expects the certificate chain to be in this order, from top to bottom: server, intermediate, root.
  • There is a known issue with UM 9.4 and 9.4P1 - the 'Alternative Names' cannot be blank. This is documented in Bug 1164539: The Setup/HTTPS Certificate page does not load after a certificate is generated without alternative names and has been fixed in UM 9.5 and later.
  • Generating the CSR remotely is supported as of AIQ UM 9.9RC1. This feature enhancement request is tracked in Bug 976954: RFE: OCUM 6.x to accept SSL certificates generated by remote CSR.

One of the following messages may be displayed when trying to install the signed certificate:

  • Failed to install certificate: A valid full certificate chain from the host certificate to the Certificate Authority's certificate must be provided.
CUSTOMER EXCLUSIVE CONTENT

Registered NetApp customers get unlimited access to our dynamic Knowledge Base.

New authoritative content is published and updated each day by our team of experts.

Current Customer or Partner?

Sign In for unlimited access

New to NetApp?

Learn more about our award-winning Support