<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vShield 5.5 - Load Balancer - Trying to implement signed certificate in vCloud Networking and Security Discussions</title>
    <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/vShield-5-5-Load-Balancer-Trying-to-implement-signed-certificate/m-p/978017#M778</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I figured out the issue. When the certificate is ready to be downloaded I need to select Base-64 encoded instead of the DER encoded. This will allow me to view the signed certificate in plain text and therefore copy/paste the signed certificate content when I import the certificate into the load balancer edge appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I did that I also ran into a different issue which I will create a new discussion on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks anyways for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Jun 2015 12:02:33 GMT</pubDate>
    <dc:creator>TimR26</dc:creator>
    <dc:date>2015-06-19T12:02:33Z</dc:date>
    <item>
      <title>vShield 5.5 - Load Balancer - Trying to implement signed certificate</title>
      <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/vShield-5-5-Load-Balancer-Trying-to-implement-signed-certificate/m-p/978014#M775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some background info for context:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vShield Mgr 5.5:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- imported Root CA cert. and a CA-signed X.509 cert.&lt;/P&gt;&lt;P&gt;- able to login to vShield Mgr. with trusted certs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vCD Cells:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- all certs signed and imported&lt;/P&gt;&lt;P&gt;- able to login directly with trusted certs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vShield Load Balancer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Virtual Machine: vcloud.ourcloudnet.com (10.10.10.1)&lt;/P&gt;&lt;P&gt;Profile applied: http/https, least_conn, 80/443, members are both vCD cells&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to have a signed and trusted cert for the load balancer address (vcloud.ourcloudnet.com). I have been trying to follow the procedures in the vShield Administration Guide page 73, but I'm getting confused with the procedure itself. When it says "You can generate a CSR and get it signed by a CA. If you generate a CSR at the global level, it is available to all vShield Edges in your inventory.", does that mean generating a CSR at the vShield Mgr level as opposed to the vShield Edge level? Am I doing this all wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need some guidance please.&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="JA" style="font-family: PalatinoLinotype-Roman; font-size: 8pt;"&gt;&lt;SPAN lang="JA" style="font-family: PalatinoLinotype-Roman; font-size: 8pt;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="mce_paste_marker"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mce_paste_marker"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 12:29:31 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCloud-Networking-and-Security/vShield-5-5-Load-Balancer-Trying-to-implement-signed-certificate/m-p/978014#M775</guid>
      <dc:creator>TimR26</dc:creator>
      <dc:date>2015-06-09T12:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: vShield 5.5 - Load Balancer - Trying to implement signed certificate</title>
      <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/vShield-5-5-Load-Balancer-Trying-to-implement-signed-certificate/m-p/978015#M776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt; When you generate at Global Level and Import at Global Level.CA signed certificate is applicable for all the edges(1:Many Mapping).However you can explicitly create CSR of each Edge(1:1 mapping) and Import only for those edges as well. Depending upon the business use case you can create/import accordingly. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;For eg: If i have multiple tenants and i'm using VSE features,i would prefer creating a separate certificate for each Edge rather doing creating CSR at Global Level and getting applied to all edges.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;However for encrypting information sent to the VCNS,we will create CA singed cert of Management software as well(1:1 mapping)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jun 2015 14:40:55 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCloud-Networking-and-Security/vShield-5-5-Load-Balancer-Trying-to-implement-signed-certificate/m-p/978015#M776</guid>
      <dc:creator>Sreec</dc:creator>
      <dc:date>2015-06-09T14:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: vShield 5.5 - Load Balancer - Trying to implement signed certificate</title>
      <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/vShield-5-5-Load-Balancer-Trying-to-implement-signed-certificate/m-p/978016#M777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get that I can create a signed cert. for the Edge, but I'm confused as to how I can import it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the procedure I have been following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I log into vCNS -&amp;gt; my data center -&amp;gt; Network Virtualization -&amp;gt; Edges, then double click my edge device -&amp;gt; configure -&amp;gt; certificates -&amp;gt; actions -&amp;gt; generate CSR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then copy the contents from the PEM Encoding text box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I log into my CA server (MS CA Services)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I click Request a Certificate -&amp;gt; click Submit a certificate request by using a base-64-encoded CMC or PKCS#10 file, or submit a renewal....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I paste the contents of the CSR and submit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CA admin approves the request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the CA server I can then download a filename.cer file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point I do back into vCNS -&amp;gt; edge certificate screen, when I click the actions -&amp;gt; import certificate, its expecting my to submit the contents of a signed certificate. Which I can't do because the filename.cer file is encrypted. Am I doing something wrong in regards to generating the CSR, the type of certificate I'm getting signed...or am I way off base with the entire signed certificate process?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jun 2015 14:14:44 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCloud-Networking-and-Security/vShield-5-5-Load-Balancer-Trying-to-implement-signed-certificate/m-p/978016#M777</guid>
      <dc:creator>TimR26</dc:creator>
      <dc:date>2015-06-16T14:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: vShield 5.5 - Load Balancer - Trying to implement signed certificate</title>
      <link>https://communities.vmware.com/t5/vCloud-Networking-and-Security/vShield-5-5-Load-Balancer-Trying-to-implement-signed-certificate/m-p/978017#M778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I figured out the issue. When the certificate is ready to be downloaded I need to select Base-64 encoded instead of the DER encoded. This will allow me to view the signed certificate in plain text and therefore copy/paste the signed certificate content when I import the certificate into the load balancer edge appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I did that I also ran into a different issue which I will create a new discussion on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks anyways for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jun 2015 12:02:33 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCloud-Networking-and-Security/vShield-5-5-Load-Balancer-Trying-to-implement-signed-certificate/m-p/978017#M778</guid>
      <dc:creator>TimR26</dc:creator>
      <dc:date>2015-06-19T12:02:33Z</dc:date>
    </item>
  </channel>
</rss>

