āļ§āļīāļ˜āļĩāļāļēāļĢāļ•āļīāļ”āļ•āļąāđ‰āļ‡ SSL āđƒāļŦāđ‰āļāļąāļš VMCenter , vCenter , VMWare Center āđ€āļžāļ·āđˆāļ­āđƒāļŠāđ‰āļ‡āļēāļ™ āđāļĨāļ°āđ€āļŠāļ·āđˆāļ­āļĄāļ•āđˆāļ­ VM Server āļ­āļĒāđˆāļēāļ‡āļ›āļĨāļ­āļ”āļ āļąāļĒāļœāđˆāļēāļ™ HTTPS āļ”āđ‰āļ§āļĒāđƒāļšāļĢāļąāļšāļĢāļ­āļ‡āļ„āļ§āļēāļĄāļ›āļĨāļ­āļ”āļ āļąāļĒāđāļ—āđ‰Â 

1. āļĨāđ‡āļ­āļ„āļ­āļīāļ™āļ—āļĩāđˆ vCenter āļ”āđ‰āļ§āļĒ user administrator āļŦāļĢāļ·āļ­ āļĢāļ°āļ”āļąāļš administrator

  • āđ„āļ›āļĒāļąāļ‡āđ€āļĄāļ™āļđ Menu > Administration > Certificates > Certificate Management.
     
  • āđ€āļĨāļ·āļ­āļ Machine SSL Certificate > Actions, āđ€āļĨāļ·āļ­āļ Import and Replace Certificate

2. āđ€āļĨāļ·āļ­āļ Replace with external CA Certificate (require private key)

 

 

2. āļ—āļģāļāļēāļĢāļ­āļąāļžāđ‚āļŦāļĨāļ” Domain.crt , Private.key , CARoot.crt

āļ—āļģāļāļēāļĢāļ­āļąāļžāđ‚āļŦāļĨāļ”āđ„āļŸāļĨāđŒ SSL Certificate āđ„āļ›āļĒāļąāļ‡ vCenter , VMCenter

  • āļāļ” Browse File : domain.crt
  • āļāļ” Browser File : CARootCertificate.crt
  • āļāļ” Browse File : private.key

āļāļ”āļ›āļļāđˆāļĄ Replace āļĢāļ°āļšāļšāļˆāļ°āđƒāļŠāđ‰āđ€āļ§āļĨāļē reload certificate 2-5 āļ™āļēāļ—āļĩ
āļŦāļĨāļąāļ‡āļˆāļēāļāļĒāļ·āļ™āļĒāļąāļ™ vCenter āļˆāļ°āļ—āļģāļāļēāļĢ restart service āđ€āļžāļ·āđˆāļ­āđƒāļŠāđ‰āļ‡āļēāļ™ certificate
āļ—āđˆāļēāļ™āļŠāļēāļĄāļēāļĢāļ–āđ€āļ‚āđ‰āļēāđƒāļŠāđ‰āļ‡āļēāļ™āļœāđˆāļēāļ™ https://{āđ‚āļ”āđ€āļĄāļ™āļˆāļąāļ”āļāļēāļĢ-vcenter} āļ‚āļ­āļ‡āļ—āđˆāļēāļ™āđ„āļ”āđ‰āļ—āļąāļ™āļ—āļĩ

 

 


āļ āļēāļĐāļēāļ­āļąāļ‡āļāļĪāļĐ
How to Configure vCenter with CA signed instance certificate

  1. Log in to vCenter and go to Menu > Administration > Certificates > Certificate Management.
  2. Under Machine SSL Certificate, click Actions > Generate Certificate Signing Request (CSR).
  3. Enter the settings to generate a CSR. Leave Common name and host as default.
  4. Sign the CSR with a trusted third-party signing authority (for example, a CA).
  5. Return to vCenter, and under Machine SSL Certificate > Actions, select Import and Replace Certificate.
  6. On the menu that appears, select Replace with certificate generated from vCenter server.
  7. On the following page, click BROWSE FILE under Machine SSL Certificate and select the signed certificate.
  8. Click BROWSE FILE under Chain of trusted root certificates and upload the chain of trusted certificates or CA certificate file.
  9. Click REPLACE and confirm that the certificate has been successfully uploaded (no errors back on the Certificate Management page). vCenter may reboot.
  • vCenter must be deployed with an FQDN.
  • Ensure vCenter is synchronized with an NTP server.
  • Users can create their own CSRs, but then must also provide the certificate key.
  • After uploading a new certificate, vCenter might log the user out. If getting an error upon a refresh, try restarting vCenter or the vCenter's management network.

āļ­āđ‰āļēāļ‡āļ­āļīāļ‡
https://kb.vmware.com/s/article/2097936
https://infohub.delltechnologies.com/l/dell-validated-design-security-configurations-for-edge-solutions-using-vmware-vsphere-7-0-1/test-5-configure-vcenter-with-ca-signed-instance-certificate

 

āđ„āļ­āđ€āļĢāļĩāļĒāļĨāļĨāļĩāđˆāđ‚āļŪāļŠ
āļŠāļģāļŦāļĢāļąāļšāļāļēāļĢāļŠāļ™āļąāļšāļŠāļ™āļļāļ™ āđāļĨāļ°āļŠāđˆāļ§āļĒāđ€āļŦāļĨāļ·āļ­
http://www.ireallyhost.com/support

 

 

 

 

āļ‚āđ‰āļ­āļāļģāļŦāļ™āļ”āđƒāļ™āļāļēāļĢāđ€āļœāļĒāđāļžāļĢāđˆāļšāļ—āļ„āļ§āļēāļĄ āļ‚āđˆāļēāļ§āļŠāļēāļĢ
** āļšāļ—āļ„āļ§āļēāļĄāļ™āļĩāđ‰āļĄāļĩāļĨāļīāļ‚āļŠāļīāļ—āļ˜āļīāđŒ āđ„āļĄāđˆāļ­āļ™āļļāļāļēāļ•āļīāđƒāļŦāđ‰āļ„āļąāļ”āļĨāļ­āļ āļ—āļģāļ‹āđ‰āļģ āļ”āļąāļ”āđāļ›āļĨāļ‡āļāđˆāļ­āļ™āđ„āļ”āđ‰āļĢāļąāļšāļ­āļ™āļļāļāļēāļ• **
āđ‚āļ›āļĢāļ”āļĢāļ°āļšāļļāđāļŦāļĨāđˆāļ‡āļ—āļĩāđˆāļĄāļē āļšāļĢāļīāļĐāļąāļ— āđ€āļ­āđ‡āļāļ‹āđŒāļ•āļĢāđ‰āļē āļ„āļ­āļĢāđŒāļ›āļ­āđ€āļĢāļŠāļąāđˆāļ™ āļˆāļģāļāļąāļ” / https://www.ireallyhost.com
āļ—āļąāđˆāļ§āđ„āļ›
āļ„āļđāđˆāļĄāļ·āļ­ / āļ§āļīāļ˜āļĩāļāļēāļĢāļ•āļīāļ”āļ•āļąāđ‰āļ‡ SSL Certificate āļŠāļģāļŦāļĢāļąāļš cPanel Web Control Panel
āļšāļĢāļīāļāļēāļĢ SSL Certificate - āđ‚āļ”āļĒāđ„āļ­āđ€āļĢāļĩāļĒāļĨāļĨāļĩāđˆāđ‚āļŪāļŠ