VMware Cloud Community
seamusobrien
Contributor
Contributor

Default Certificates

I was wondering if somebody could point me to an article or blog post about how to replace the default SRM certificates with ones that are publicly signed such as ones by Microsoft CA

I will be deploying SRM 5.5 in a secure environment. The SRM installation documentation is lacking in this area.

Thanks in advance

Reply
0 Kudos
2 Replies
Madmax01
Expert
Expert

Hi theire Smiley Wink

the whole SSL Topic is Lacking for each of the Vmware installer.

In time like today where security is getting highly more and more important > it should be imortant through Installer beeing able to check the SSL Certs and that Costumer is having a Possibility to interact with creating new ones for theire likeness.

they have a commandline tool: http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=205734...

i don't have a SRM and i use currently self-Signed ones - because only internally connections. > theirefore don't have experiences with the upper tool.

Maybe with "other Services" you're able to generating and replacing the SRM also.

Correct me if i'am wrong > but don't use SRM the SSL Cert of the vCenter?  so i think once you have ne ones for vCenter > then you could restart installer and do also re/register to vCenter. SRM has to accept the SSL Cert.

So i think once you're SRM has default > then you're vCenter has also default Cert.

Best regards

Max

Reply
0 Kudos
asenov
VMware Employee
VMware Employee

Hi seamusobrien,

Although the process of replacing the default SRM certificates with valid ones is not a straightforward one, there is pretty good documentation about it. You should do the following things:

1. Get valid certificates which meet the requirements of the SRM server - you could find the details here: Site Recovery Manager 5.5 Documentation Center

2. Make sure that the corresponding vCenter servers also use trusted certificates - this could be accomplished by replacing the default certificates with trusted ones using the tool mentioned by Madmax01 ( http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=205734...)

3. Run SRM installation in Modify mode and replace the certificates - more info about that could be found here: Site Recovery Manager 5.5 Documentation Center 

Regards,

Asen

Reply
0 Kudos