Update Certificates

Use the following optional procedure to install a public CA certificate on an interface or to revert an interface to use the default self-signed certificate.
  1. Go to Administration > System > Network Setup.
  2. Select the interface for which you want to update certificates.
  3. Select Certificates to view certificate information for that interface.
  4. Select one of the following four certificate options and complete the required substeps for that option:
    Table 1. Certificate Update Options
    Field Description
    Replace/Install Interface Certificate Select this option if you want to generate a CA certificate for this interface using Universal Compute Platform's CSR request form. Complete the following substeps:
    1. Go to Generate CSR and create a certificate request that you can present to a CA in exchange for a CA certificate.
    2. Once you've obtained the certificate, select the first Choose File and then select the certificate (.cer file).
    3. Optional. If you have a root certificate chain, select the second Choose File and select the certificate chain (.PEM file).
    Replace/Install Interface Certificate and key from a single file Select this option if you want to install a certificate file that you generated on an external CA site. Complete the following substeps:
    1. Select the first Choose file and select the PKCS#12 certificate (.pfx file).
    2. Enter the Private Key for the certificate.
    3. Optional. If you have a root certificate chain, select the second Choose File and then select the certificate chain (.PEM file).
    Replace/Install Interface Certificate and key from separate files Select this option to upload certificates where the certificate, key, and CA root chain are in different files. For example, this may occur if you generated the files in Linux with an OpenSSL connection: Complete the following substeps:
    1. Select the first Choose File and select the certificate file (.cer file).
    2. Select the second Choose File and select the private key (.key file).
    3. Optional. If you have a root certificate chain, select the third Choose File and select the public CA root chain (.PEM file).
    Reset Interface to the factory default certificate and key Select this option if you want to reset this interface to use the factory-default self-signed certificate. When you select this option, any certificates that you installed on this interface get removed.
  5. Select Save.
    Note

    Note

    A server restart is triggered after cerificates are applied on the following topologies:
    • When applied or reset on the Admin topology.
    • When applied or reset on System topologies where Management Traffic is enabled.