<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DFM SSL and trust chains in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/DFM-SSL-and-trust-chains/m-p/125423#M22489</link>
    <description>&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to use client signed SSL certificates for the DFM administration page (OnCommane Core Package 5.2.1). &amp;nbsp;I've set up ssl with the "dfm ssl server setup" command and then generated a request to be signed by the client. &amp;nbsp;Once signed, I installed it with the "dfm ssl server import &amp;lt;filename&amp;gt;" command which was successful. &amp;nbsp;After restarting the http service, I can access the web GUI but the certificate is not trusted. &amp;nbsp;I believe this has something to do with the fact the signed certificate contains a "trust chain" which is not being picked up. &amp;nbsp;The file I imported contains the DFM certificate first, then 2 certificate issuers (intermediate and root). &amp;nbsp;If I import the same file but in the opposite direction (root first DFM last), the hhtp service fails to start. &amp;nbsp;My question is, does DFM not support trust chains or is there an undocumented way of getting this to work? &amp;nbsp;The basic error I get in Firefox is that the certificate is not trusted because the issuer certificate is unknown.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 18:15:29 GMT</pubDate>
    <dc:creator>mrosebro</dc:creator>
    <dc:date>2025-06-04T18:15:29Z</dc:date>
    <item>
      <title>DFM SSL and trust chains</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/DFM-SSL-and-trust-chains/m-p/125423#M22489</link>
      <description>&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to use client signed SSL certificates for the DFM administration page (OnCommane Core Package 5.2.1). &amp;nbsp;I've set up ssl with the "dfm ssl server setup" command and then generated a request to be signed by the client. &amp;nbsp;Once signed, I installed it with the "dfm ssl server import &amp;lt;filename&amp;gt;" command which was successful. &amp;nbsp;After restarting the http service, I can access the web GUI but the certificate is not trusted. &amp;nbsp;I believe this has something to do with the fact the signed certificate contains a "trust chain" which is not being picked up. &amp;nbsp;The file I imported contains the DFM certificate first, then 2 certificate issuers (intermediate and root). &amp;nbsp;If I import the same file but in the opposite direction (root first DFM last), the hhtp service fails to start. &amp;nbsp;My question is, does DFM not support trust chains or is there an undocumented way of getting this to work? &amp;nbsp;The basic error I get in Firefox is that the certificate is not trusted because the issuer certificate is unknown.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 18:15:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/DFM-SSL-and-trust-chains/m-p/125423#M22489</guid>
      <dc:creator>mrosebro</dc:creator>
      <dc:date>2025-06-04T18:15:29Z</dc:date>
    </item>
  </channel>
</rss>

