u/BeneficialBill6037

▲ 6 r/vmware

How to replace STS signing cert with custom signed cert?

I work in the DOD and I need to renew our STS signing cert since it is expiring soon. I've replaced the machine SSL with no issues but that's not the case with STS.

How do I generate a CSR for STS? I know I have to manually create a pem file with the private key and full chain but can't figure out how to generate a csr. Any help is appreciated!

reddit.com
u/BeneficialBill6037 — 5 days ago
▲ 12 r/vmware

VSphere, ESXi, and iDRAC certs are expiring soon. I'm building an SOP for our air-gapped site and want to avoid a lockout.

My plan is to do the following:

CSRs: Generate and sign via NPE Portal.
vCenter: Replace Machine SSL via GUI (Is CLI safer for custom certs?).
ESXi: Can I use the vCenter GUI for custom certs instead of SSH?
iDRAC: Standard GUI import.

Question:
STS Cert: vCenter says it's expiring. Do I just hit "Renew" in the GUI, or does this need a custom cert from NPE?

Horizon/10zig: What needs to be updated once the vCenter thumbprint changes?

Any precautions I should watch out for? Backups are verified and solid. Any advice from folks who've done this in a secure environment? Thank you all!

reddit.com
u/BeneficialBill6037 — 17 days ago

I'll be coming from Pearl City and is planning on going to Spam Jam tomorrow. I plan on getting there from 6pm onwards. I'm already anticipating traffic and since it's my first time going, I figured it'll be worth it.

Where is the best place to park? I thought about taking the Bus too but i'm not really familiar with the bus system. I'll be going alone so I figured driving would be more ideal.

u/BeneficialBill6037 — 28 days ago