<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Install https certificate on OCUM server appliance 6.2 in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/103309#M18284</link>
    <description>&lt;P&gt;Francois,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might need a certificate authority ( local ), once you provide them the existing OCUM certificate and the server name, in my case provided a full chain p7b which was later converted to PEM format and later renamed to .cer .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sometimes needs troubleshooting with someone knowledgeable on the CA side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2015 16:43:58 GMT</pubDate>
    <dc:creator>trentino123</dc:creator>
    <dc:date>2015-04-16T16:43:58Z</dc:date>
    <item>
      <title>Install https certificate on OCUM server appliance 6.2</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/102965#M18227</link>
      <description>&lt;P&gt;I tried to install certificated in PEM format on ocum 6.2 Appliance.&lt;/P&gt;&lt;P&gt;The following message appears though certificate chaine is integrated in file.&lt;/P&gt;&lt;P&gt;"a valid full certificate chain from the host certificate to the certificate authority's certificate must be provided."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know what's append here and how to solve this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Help appreciated.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;François&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 11:30:27 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/102965#M18227</guid>
      <dc:creator>francoisbnc</dc:creator>
      <dc:date>2015-04-09T11:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Install https certificate on OCUM server appliance 6.2</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/102977#M18228</link>
      <description>&lt;P&gt;Hey Francois,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not a OCUM guy, but I know a thing or two about PKI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That error message basically is saying that you are trying to install a host cert into a system, but that system's certificate store does NOT trust the signing authority that the host cert was signed by. Windows has its own cert store, but applications may have their own - I am an OCI SE, and OCI has its own java keystore that by default has a self-signed cert in it to support SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may need to first install the signing certificate authority's public cert into OCUM before the host cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most serious certificate deployments involve an offline root authority, and the day to day certificates are signed by intermediate certificate authorities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may need to install both the intermedia CA certs, as well as the root CA cert (if the root is not already trusted), before installing the host cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Earlier this week I was helping a customer get signed host certs working in OCI - we needed to delete the self signed cert, install the root cert, 2 intermediate CA certs, and the host cert&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 13:28:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/102977#M18228</guid>
      <dc:creator>ostiguy</dc:creator>
      <dc:date>2015-04-09T13:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Install https certificate on OCUM server appliance 6.2</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/102979#M18229</link>
      <description>&lt;P&gt;Hello Matt,&lt;/P&gt;&lt;P&gt;As I can see, I&amp;nbsp;don't have so many choice to install certificates as it's a appliance where I don't have root access on.&lt;/P&gt;&lt;P&gt;I tried to install separately, starting with root authority but same message appears&amp;nbsp;&lt;/P&gt;&lt;P&gt;François&lt;/P&gt;&lt;P&gt;&lt;IMG height="125" alt="2015-04-09_15-50-56.bmp" width="266" src="https://community.netapp.com/t5/image/serverpage/image-id/2537iD76B4DE24FC3CEC5/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" title="2015-04-09_15-50-56.bmp" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 14:12:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/102979#M18229</guid>
      <dc:creator>francoisbnc</dc:creator>
      <dc:date>2015-04-09T14:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Install https certificate on OCUM server appliance 6.2</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/103309#M18284</link>
      <description>&lt;P&gt;Francois,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might need a certificate authority ( local ), once you provide them the existing OCUM certificate and the server name, in my case provided a full chain p7b which was later converted to PEM format and later renamed to .cer .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sometimes needs troubleshooting with someone knowledgeable on the CA side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2015 16:43:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/103309#M18284</guid>
      <dc:creator>trentino123</dc:creator>
      <dc:date>2015-04-16T16:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Install https certificate on OCUM server appliance 6.2</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/107215#M18910</link>
      <description>&lt;P&gt;Francois,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just ran into the same issue as you did with OCUM 6.2 and was able to resolve. Your CA probably issues certs in a .p7b format. So what you need to do is convert the file to .cer via OpenSSL. Below are the commands:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;openssl pkcs7 -print_certs -in &amp;lt;path to .p7b&amp;gt; -out &amp;lt;path to .cer&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I converted the certificate, it imported successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2015 13:09:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/107215#M18910</guid>
      <dc:creator>ANTONIO_CHIARIZIA_CT</dc:creator>
      <dc:date>2015-07-10T13:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Install https certificate on OCUM server appliance 6.2</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/107526#M18961</link>
      <description>&lt;P&gt;And an addition to the order of the file you are importing.&amp;nbsp; The cert data must be in a specific order, what I will call "inside out".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;start PEM cert chain file, this line should not be included in the cert chain file&amp;gt;&lt;BR /&gt;OPM or UM host cert (PEM format)&lt;BR /&gt;Intermediate #1 (if present, PEM format)&lt;BR /&gt;Intermediate #2 (if present, PEM format)&lt;BR /&gt;Intermediate … (if needed, PEM format)&lt;BR /&gt;Root (PEM format)&lt;BR /&gt;&amp;lt;end of PEM cert chain file, this line should not be included in the cert chain file&amp;gt;&lt;BR /&gt;&lt;BR /&gt;You will need at least two entries in the cert chain file:&amp;nbsp; OPM or UM (host) and the Root (CA cert).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The error message ""a valid full certificate chain from the host certificate to the certificate authority's certificate must be provided." alludes to this "inside-out" format, which is why I added the clarification above.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2015 13:57:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Install-https-certificate-on-OCUM-server-appliance-6-2/m-p/107526#M18961</guid>
      <dc:creator>marz</dc:creator>
      <dc:date>2015-07-22T13:57:07Z</dc:date>
    </item>
  </channel>
</rss>

