Upload Your Certificates

Upload Your Certificates

There are two ways to upload your server certificate and private key for the Web UI on the appliance.

  • Generate a CSR and import the certificate
  • Import certificates and private key

Generate a CSR and Import the Certificate

To generate a CSR and import the certificate:

  1. Access the appliance console using ssh.
  2. Log in to the appliance using the nsadmin/nsappliance credentials. An nsshell opens.
  3. Enter configure to enter the nsshell configure mode.
  4. Generate CSR, copy the CSR from the CLI using the show command, and then use that to get a signed certificate.
    run request certificate generate web-ui certificate-request 
    city <city>
    common-name <common name for the certificate> 
    country <two-letter country code>
    days <number of the days the certificate is valid for>
    email-address <email address> 
    organization <name of the organization>
    organizational-unit <organizational-unit>
    state <state or province>
    show management-plane web-ui csr
  5. Enter this command: set management-plane web-ui server-cert.
  6. Copy and paste just your single PEM-formatted server certificate (no keys). Enter one or more lines of input. When done, press Ctrl-D.
  7. To import CA certificates, enter this command: set management-plane web-ui server-intermediate-ca-chain.
  8. Copy and paste any additional PEM-formatted CA certificates to send with the server cert (no keys) using this command: The ordering should be from the lowest certificate in the chain to the root. Enter one or more lines of input. When done, press Ctrl-D.
  9. Enter save to activate your changes.
  10. Enter exit to leave the configure mode.
  11. Enter exit to leave the nsshell and exit the appliance console.

Import Certificates and Private Key

To import certificates and private key:

  1. Access the appliance console using ssh.
  2. Log in to the appliance using the nsadmin/nsappliance credentials. An nsshell opens.
  3. Enter configure to enter the nsshell configure mode.
  4. Enter this command: set management-plane web-ui server-cert.
  5. Copy and paste just your single PEM-formatted server certificate (no keys). Enter one or more lines of input. When done, press Ctrl-D.
  6. Enter this command: set management-plane web-ui server-key.
  7. Copy and paste just your single PEM-formatted server RSA private key (no certificates). Enter one or more lines of input. When done, press Ctrl-D.
  8. To import CA certificates, enter this command: set management-plane web-ui server-intermediate-ca-chain.
  9. Copy and paste any additional PEM-formatted CA certificates to send with the server cert (no keys) using this command: The ordering should be from the lowest certificate in the chain to the root. Enter one or more lines of input. When done, press Ctrl-D.
  10. Enter save to activate your changes.
  11. Enter exit to leave the configure mode.
  12. Enter exit to leave the nsshell and exit the appliance console.
Share this Doc

Upload Your Certificates

Or copy link

In this topic ...