<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NSX-T 3.1 renew self signed certificates in VMware NSX Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-T-3-1-renew-self-signed-certificates/m-p/2951856#M16009</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;1. Can we extend the duration of an expired certificate?&lt;BR /&gt;2. You advised entering SAN (VIP and three manager nodes with FQDN) for a certificate, but in the CSR generating process we only can enter the Common name, there is no section for entering SAN?&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2023 08:01:58 GMT</pubDate>
    <dc:creator>salarmehdizadeh</dc:creator>
    <dc:date>2023-02-01T08:01:58Z</dc:date>
    <item>
      <title>NSX-T 3.1 renew self signed certificates</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-T-3-1-renew-self-signed-certificates/m-p/2940908#M15738</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;Need to renew the NSX-T certificates. I will use self signed ones. I have a cluster with 3 managers.&lt;/P&gt;&lt;P&gt;I notice that the actual certificates of mp-cluster and the tomcat certificate for node 1, are issued to the hostname of manager one, and not to the fqdn. For node2 and node 3 the certificates are issued for the fqdns.&lt;/P&gt;&lt;P&gt;My question is:&lt;/P&gt;&lt;P&gt;When i generate new certificates, in this case for node1 and mp-cluster, should i use the fqdn, or only the hostname?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 13:44:31 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-T-3-1-renew-self-signed-certificates/m-p/2940908#M15738</guid>
      <dc:creator>Petersaints</dc:creator>
      <dc:date>2022-11-27T13:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: NSX-T 3.1 renew self signed certificates</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-T-3-1-renew-self-signed-certificates/m-p/2940930#M15740</link>
      <description>&lt;P&gt;If you can, issue a certificate to the FQDN of the vIP and add the individual host names as Subject Alternative Names (SANs) along with the vIP ID. You should have 4 total SANs, unless you have the ability to also add the IP address (then it should be &lt;img class="lia-deferred-image lia-image-emoji" src="https://communities.vmware.com/html/@453E19AA97B60EFA5AACFC0B3C3D3845/emoticons/1f60e.png" alt=":smiling_face_with_sunglasses:" title=":smiling_face_with_sunglasses:" /&gt;&lt;/P&gt;&lt;P&gt;This will allow your NSX managers to authenticate either when addressed individually or as a cluster member.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 18:14:46 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-T-3-1-renew-self-signed-certificates/m-p/2940930#M15740</guid>
      <dc:creator>engyak</dc:creator>
      <dc:date>2022-11-27T18:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: NSX-T 3.1 renew self signed certificates</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-T-3-1-renew-self-signed-certificates/m-p/2951856#M16009</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;1. Can we extend the duration of an expired certificate?&lt;BR /&gt;2. You advised entering SAN (VIP and three manager nodes with FQDN) for a certificate, but in the CSR generating process we only can enter the Common name, there is no section for entering SAN?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 08:01:58 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-T-3-1-renew-self-signed-certificates/m-p/2951856#M16009</guid>
      <dc:creator>salarmehdizadeh</dc:creator>
      <dc:date>2023-02-01T08:01:58Z</dc:date>
    </item>
  </channel>
</rss>

