Manage ONTAP tools certificates
A self-signed certificate is generated for ONTAP tools and VASA Provider by default during deployment. You can use the ONTAP tools Manager interface to renew this certificate or replace it with a custom CA certificate. In multi-vCenter deployments, using custom CA certificates is required.
|
|
If certificates expire without timely renewal, ONTAP tools stops functioning. Renew certificates before expiration to maintain continuous operation and prevent service disruption. |
You should have the following before you begin:
-
The domain name mapped to the ONTAP tools IP address.
-
Successful nslookup of the domain name, confirming it resolves to the correct IP address.
-
Certificates created with the domain name and the ONTAP tools IP address.
|
|
An ONTAP tools IP address should map to a fully qualified domain name (FQDN). Certificates should contain the same FQDN mapped to the ONTAP tools IP address in subject or subject alternative names. |
|
|
You cannot switch from a CA-signed to a self-signed certificate. |
ONTAP tools tab shows details like certificate type (self-signed/CA signed) and domain name. During deployment, self-signed certificate is generated by default. You can renew the certificate or upgrade the certificate to CA.
-
Launch ONTAP tools Manager from a web browser:
https://<ONTAPtoolsIP>:8443/virtualization/ui/ -
Log in with the ONTAP tools for VMware vSphere administrator credentials you provided during deployment.
-
Select Certificates > ONTAP tools > Renew to renew the certificates.
You can renew the certificate if it has expired or is nearing its expiration date. The renew option is available when the certificate type is self-signed or CA-signed. In the pop-up window, provide the server certificate, private key, root CA, and intermediate certificate details.
The system will be offline until the certificate is renewed, and you will be logged out of the ONTAP tools Manager interface. -
To upgrade the self-signed certificate to custom CA certificate, select Certificates > ONTAP tools > Upgrade to CA option.
-
In the pop-up window, upload the server certificate, server certificate private key, root CA certificate, and intermediate certificate files.
-
Enter the FQDN mapped to the ONTAP tools IP address (formerly load balancer IP) for which you generated this certificate, and upgrade the certificate.
The system will be offline until the upgrade is complete, and you will be logged out of the ONTAP tools Manager interface.
-
ONTAP tools for VMware vSphere is deployed with a self-signed certificate for VASA Provider. With this, only one vCenter Server instance can be managed for vVols datastores. When you manage multiple vCenter Server instances and want to enable vVols capability on them, you need to change the self-signed certificate to a custom CA certificate.
-
Launch ONTAP tools Manager from a web browser:
https://<ONTAPtoolsIP>:8443/virtualization/ui/ -
Log in with the ONTAP tools for VMware vSphere administrator credentials you provided during deployment.
-
Select Certificates > VASA Provider or ONTAP tools > Renew to renew the certificates.
-
Select Certificates > VASA Provider or ONTAP tools > Upgrade to CA to upgrade the self-signed certificate to custom CA certificate.
-
In the pop-up window, upload the server certificate, server certificate private key, root CA certificate, and intermediate certificate files.
-
Enter the FQDN mapped to the ONTAP tools IP address (formerly load balancer IP) for which you generated this certificate, and upgrade the certificate.
The system will be offline until the upgrade is complete, and you will be logged out of the ONTAP tools Manager interface.
-
Beginning with ONTAP tools 10.5, certificate validity changed from 10 years to 1 year. Beginning with ONTAP tools 10.5P2, during ONTAP tools upgrade, internal service communication certificates are automatically renewed, and the gateway self-signed certificate is also refreshed.
Use this maintenance console option to manually refresh internal service communication certificates when you receive an alert that an internal certificate is nearing expiration, or if ONTAP tools has not been upgraded within one year. Beginning with ONTAP tools 10.5P2, upgrades automatically renew these certificates. The refreshed certificates continue to use a one-year validity period (365 days), which helps meet audit requirements.
-
Log in to the vCenter Server.
-
Locate the ONTAP tools VM and launch the web console.
-
Log in using the
maintcredentials. -
Enter
2to select System Configuration. -
Enter
9to select Refresh ONTAP tools services certificates.
|
|
This action restarts all services and might cause downtime or disruption. To continue, acknowledge the warning by typing y, and then the refresh process starts.
|