In this article, I am going to guide you how to Replace the certificate for vDIM (VMware Identity Manager Integration)
You have to SSH to the Appliance and type to su
become a root.
Run the OpenSSL command with the config file (pre-defined certificate config file)openssl req -new -keyout wsa001.key -out wsa001.csr
oropenssl req -new
-config wsa001.cnf
-keyout wsa001.key -out wsa001.csr
export .csr and .key file
Open the wsa001.csr
CSR file in a notepad – “select all” + copy + paste into the Certificate Authority Web
Launch Certificate Authority Web
click on “request a certificate
data:image/s3,"s3://crabby-images/c77c9/c77c996df83015a21ac6294aaac12db3672873f9" alt=""
data:image/s3,"s3://crabby-images/133bb/133bbadfd02c0256c75787b594cfe1a7f9c535c5" alt=""
copy and paste the content from the “wsa001.csr
” (opened in NotePad) into the box identifed next to
“Base-64-encoded cert request”
select the certificate template (if a specific template hasn’t been created, select “Web Server” as the
template)
-> click on submit
data:image/s3,"s3://crabby-images/899dd/899dd151958e4735a61f1fc02a1372ddfdf9499b" alt=""
Select the “Base 64 encoded” radio button and “download the certificate” – rename to “was001.cer”
Download a Base-64 encoded rootCA certificate from Certificate Authority Web
Open WSA001.CER and RootCA in Notepad
copy the content “wsa001.CER
” and paste it into the RootCA file.
copy all content (Ctrl+A and Ctrl+C)
log in into WAS001 Web interface
data:image/s3,"s3://crabby-images/73720/737209786a888079d0c1a028bb17172933877dc5" alt=""
Go to Applaince Settings and Manage Configuration
data:image/s3,"s3://crabby-images/b02bb/b02bba11b3a070b81f408a52da65f35a4a0b528c" alt=""
Provide password one more time
data:image/s3,"s3://crabby-images/33af1/33af1b7654b81d30facad23ac41369e1d7bf24c0" alt=""
Go to Install SSL Certificate
Paste the WSA001 and RootCa content in the SSL Certificate Chain and Paste cthe ontent of Private key to the Private Key section
data:image/s3,"s3://crabby-images/8fca4/8fca4cee3a627e998884ea09596bad249f8e2f88" alt=""
then commit the change by press Save button
confirm
data:image/s3,"s3://crabby-images/c52f2/c52f2e8d60d3593020ea406237cbcb84442336ab" alt=""
Services will be restarted
data:image/s3,"s3://crabby-images/9071c/9071c260bbec10656e0ced2ebced635ad402cae0" alt=""
renewal of cert will break integration to a solution like NSX-T. in Part 2 I will guide you to
reconnect NSX-T again.
I hope this article has been informative. thank you for reading.
This blog was… how do you say it? Relevant!! Finally I’ve found something that helped me.
Cheers!