Skip to main content

Manage certificates on an AFX storage system

Contributors dmp-netapp

Depending on your environment, you'll need to create and manage digital certificates as part of administering AFX. There are several related tasks you can perform.

Generate a certificate signing request

To get started using a digital certificate, you need to generate a certificate signing request (CSR). A CSR is used to request a signed certificate from a certificate authority (CA).As part of this, ONTAP creates a public/private key pair and includes the public key in the CSR.

Steps
  1. In System Manager, select Cluster and then Settings.

  2. Under Security and next to Certificates, select blue arrow pointing to the right

  3. Select blue rectangle containing a plus sign followed by the words generate csr.

  4. Provide the subject common name and country; optionally provide the organization and organizational unit.

  5. To change the default values which will define the certificate, select two arrows facing diagonally opposite directions followed by the words more options and make the desired updates.

  6. Select Generate.

Result

You have generated a CSR which can be used to request a public key certificate.

Add a trusted certificate authority

ONTAP provides a default set of trusted root certificates for use with Transport Layer Security (TLS) and other protocols. You can add additional trusted certificate authorities as needed.

Steps
  1. In System Manager, select Cluster and then Settings.

  2. Under Security and next to Certificates, select blue arrow pointing to the right.

  3. Select the tab Trusted certificate authorities and then select blue rectangle containing a plus sign followed by the word add in white letters.

  4. Provide the configuration information, including the name, scope, common name, type, and certificate details; you can import the certificate instead by selecting Import.

  5. Select Add.

Result

You have added a trusted certificate authority to your AFX system.

Renew or delete a trusted certificate authority

Trusted certificate authorities must be renewed annually. If you do not want to renew an expired certificate, you should delete it.

Steps
  1. Select Cluster and then Settings.

  2. Under Security and next to Certificates, select blue arrow pointing to the right.

  3. Select the tab Trusted certificate authorities.

  4. Select the trust certificate authority that you want to renew or delete.

  5. Renew or delete the certificate authority.

    To renew the certificate authority, do this: To delete the certificate authority, do this:
    1. Select three vertical blue dots and then select Renew.

    2. Enter or import the certificate information and select Renew.

    1. Select three vertical blue dots and then select Delete.

    2. Confirm that you want to delete and select Delete.

Result

You have renewed or deleted an existing trusted certificate authority on your AFX system.

Add a client/server certificate or local certificate authority

You can add a client/server certificate or a local certificate authority as part of enabling secure web services.

Steps
  1. In System Manager, select Cluster and then Settings.

  2. Under Security and next to Certificates, select blue arrow pointing to the right.

  3. Select either Client/server certificates or Local certificate authorities as needed.

  4. Add the certificate information and select Save.

Result

You have added a new client/server certificate or local authorities to your AFX system.

Renew or delete a client/server certificate or local certificate authorities

Client/server certificates and local certificate authorities must be renewed annually. If you do not want to renew an expired certificate or local certificate authorities, you should delete them.

Steps
  1. Select Cluster and then Settings.

  2. Under Security and next to Certificates, select blue arrow pointing to the right.

  3. Select either Client/server certificates or Local certificate authorities as needed.

  4. Select the certificate you want to renew or delete.

  5. Renew or delete the certificate authority.

    To renew the certificate authority, do this: To delete the certificate authority, do this:
    1. Select three vertical blue dots and then select Renew.

    2. Enter or import the certificate information and select Renew.

    Select three vertical blue dots and then select Delete.

Result

You have renewed or deleted an existing client/server certificate or local certificate authority on your AFX system.