Dell PowerEdge R830 Integrated Remote Access Controller 8 Version 2.70.70.70 U - Page 94

Uploading server certificate using RACADM, Viewing server certificate

Page 94 highlights

4. A pop-up message is displayed asking you to reset iDRAC immediately or at a later time. Click Reset iDRAC or Reset iDRAC Later as required. iDRAC resets and the new certificate is applied. The iDRAC is not available for a few minutes during the reset. NOTE: You must reset iDRAC to apply the new certificate. Until iDRAC is reset, the existing certificate is active. Uploading server certificate using RACADM To upload the SSL server certificate, use the sslcertupload command. For more information, see the RACADM Command Line Reference Guide for iDRAC available at dell.com/idracmanuals. If the CSR is generated outside of iDRAC with a private key available, then to upload the certificate to iDRAC: 1. Send the CSR to a well-known root CA. CA signs the CSR and the CSR becomes a valid certificate. 2. Upload the private key using the remote racadm sslkeyupload command. 3. Upload the signed certificate to iDRAC using the remote racadm sslcertupload command. The new certificate is uploaded iDRAC. A message is displayed asking you to reset iDRAC. 4. Run the racadm racreset command to reset iDRAC. iDRAC resets and the new certificate is applied. The iDRAC is not available for a few minutes during the reset. NOTE: You must reset iDRAC to apply the new certificate. Until iDRAC is reset, the existing certificate is active. Viewing server certificate You can view the SSL server certificate that is currently being used in iDRAC. Related concepts SSL server certificates Viewing server certificate using web interface In the iDRAC Web interface, go to Overview > iDRAC Settings > Network > SSL. The SSL page displays the SSL server certificate that is currently in use at the top of the page. Viewing server certificate using RACADM To view the SSL server certificate, use the sslcertview command. For more information, see the iDRAC RACADM Command Line Interface Reference Guide available at dell.com/idracmanuals. Uploading custom signing certificate You can upload a custom signing certificate to sign the SSL certificate. SHA-2 certificates are also supported. Uploading custom signing certificate using web interface To upload the custom signing certificate using iDRAC web interface: 1. Go to Overview > iDRAC Settings > Network > SSL. The SSL page is displayed. 2. Under Custom SSL Certificate Signing Certificate, select Upload Custom SSL Certificate Signing Certificate and click Next. The Upload Custom SSL Certificate Signing Certificate page is displayed. 3. Click Browse and select the custom SSL certificate signing certificate file. Only Public-Key Cryptography Standards #12 (PKCS #12) compliant certificate is supported. 4. If the certificate is password protected, in the PKCS#12 Password field, enter the password. 5. Click Apply. The certificate is uploaded to iDRAC. 6. A pop-up message is displayed asking you to reset iDRAC immediately or at a later time. Click Reset iDRAC or Reset iDRAC Later as required. After iDRAC resets, the new certificate is applied. The iDRAC is not available for a few minutes during the reset. 94 Configuring iDRAC

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298

4.
A pop-up message is displayed asking you to reset iDRAC immediately or at a later time. Click
Reset iDRAC
or
Reset iDRAC Later
as
required.
iDRAC resets and the new certificate is applied. The iDRAC is not available for a few minutes during the reset.
NOTE:
You must reset iDRAC to apply the new certificate. Until iDRAC is reset, the existing certificate is active.
Uploading server certificate using RACADM
To upload the SSL server certificate, use the
sslcertupload
command. For more information, see the
RACADM Command Line
Reference Guide for iDRAC
available at
dell.com/idracmanuals
.
If the CSR is generated outside of iDRAC with a private key available, then to upload the certificate to iDRAC:
1.
Send the CSR to a well-known root CA. CA signs the CSR and the CSR becomes a valid certificate.
2.
Upload the private key using the remote racadm
sslkeyupload
command.
3.
Upload the signed certificate to iDRAC using the remote racadm
sslcertupload
command.
The new certificate is uploaded iDRAC. A message is displayed asking you to reset iDRAC.
4.
Run the racadm
racreset
command to reset iDRAC.
iDRAC resets and the new certificate is applied. The iDRAC is not available for a few minutes during the reset.
NOTE:
You must reset iDRAC to apply the new certificate. Until iDRAC is reset, the existing certificate is active.
Viewing server certificate
You can view the SSL server certificate that is currently being used in iDRAC.
Related concepts
SSL server certificates
Viewing server certificate using web interface
In the iDRAC Web interface, go to
Overview
>
iDRAC Settings
>
Network
>
SSL
. The
SSL
page displays the SSL server certificate
that is currently in use at the top of the page.
Viewing server certificate using RACADM
To view the SSL server certificate, use the
sslcertview
command.
For more information, see the
iDRAC RACADM Command Line Interface Reference Guide
available at
dell.com/idracmanuals
.
Uploading custom signing certificate
You can upload a custom signing certificate to sign the SSL certificate. SHA-2 certificates are also supported.
Uploading custom signing certificate using web interface
To upload the custom signing certificate using iDRAC web interface:
1.
Go to
Overview
>
iDRAC Settings
>
Network
>
SSL
.
The
SSL
page is displayed.
2.
Under
Custom SSL Certificate Signing Certificate
, select
Upload Custom SSL Certificate Signing Certificate
and click
Next
.
The
Upload Custom SSL Certificate Signing Certificate
page is displayed.
3.
Click
Browse
and select the custom SSL certificate signing certificate file.
Only Public-Key Cryptography Standards #12 (PKCS #12) compliant certificate is supported.
4.
If the certificate is password protected, in the
PKCS#12 Password
field, enter the password.
5.
Click
Apply
.
The certificate is uploaded to iDRAC.
6.
A pop-up message is displayed asking you to reset iDRAC immediately or at a later time. Click
Reset iDRAC
or
Reset iDRAC Later
as
required.
After iDRAC resets, the new certificate is applied. The iDRAC is not available for a few minutes during the reset.
94
Configuring iDRAC