Use this procedure to generate and install a custom self-signed certificate for all nodes in your cluster. If you are using a KMIP server you can choose to use this certificate for the KMIP server as well.
- Log into the Cryptographic Security Platform Vault Management webGUI using an account with Domain Admin privileges.
- In the top right, click the Switch to Appliance Management link.
- In the top menu bar, click Cluster.
Click the Cluster tab and select Actions > Generate and Install Self-Signed Certificate.
Complete the following:
Field
Description
Common Name
The name to associate with this certificate. This field is required.
Locality
Optional. The locale to associate with this certificate.
State
Optional. The state to associate with this certificate.
Subject Alternative Names
Optional. The host names that will be protected by this certificate. If you want to use the same certificate on multiple Cryptographic Security Platform Vault nodes in the system for the external web server, add all of the Cryptographic Security Platform Vault URLs to this list.
By default, Cryptographic Security Platform Vault adds the URL of the selected Cryptographic Security Platform Vault node. You can change or delete the default URL as long as you end up specifying at least one Cryptographic Security Platform Vault node in this field.
Key Size
Optional. Select the key size that you want to use. The default is 4096 bytes.
Country
The ISO 3166-1 alpha-2 code of country to associate with this certificate. This field is required.
Organization
Optional. The organization to associate with this request.
Organization Unit
Optional. The organizational unit associate with this request.
Validity (Days)
Optional. The number of days this certificate will be valid. The default is 365 days.
Use this certificate for KMIP
Select Yes if you are using a KMIP server along with the Cryptographic Security Platform Vault for KMIP and want to use this certificate for the KMIP server as well.
The default is No.
Click Generate and Install.