08-06-2018 09:56 PM - edited 03-08-2019 05:31 PM
I installed Vmanage on a virtual machine. On Vmanage i selected manual root certificate and generated certificate with "Generate CSR", it generated a .csr file, now i wanted to install this certificate for vManage and when uploading the certificate it gives me error saying "cannot decrypt serial number from the certificate".? Where do i get the serial number, its a VM? Is this the right way to do it, do i need to install this certificate for vManage?
Solved! Go to Solution.
01-13-2021 05:23 AM
I am also facing the same problem, any solution?
08-09-2018 10:44 AM
CSR is certificate signing request. you would generate the request and then use Symantec to sign the request.
You can still do automated with on premise vmanage as long as you have internet access. If you want to use your own CA then it becomes a bit more complicated.
08-30-2018 06:15 AM
I am actually stuck at this stage:
I have installed a OVA image in my a lab VM environment, when i do generate CSR for vmanage it says:
Failed to get CSR signed
Unable to get response from signing server https://certmanager-webservices.websecurity.symantec.com/vswebservices/rest/services/enroll
even though from vmanage command line i can ping 8.8.8.8.
08-30-2018 06:59 PM
Sounds like you are building a lab, are you? In this case you should not use Digicert (ex-Symmantec) certificates. Digicert certificates should be used for production deployments. For lab you should use private certificates. You can use tools like tinyCA (Ubuntu) or XCA (Mac) to sign CSRs generated on controllers. The process is:
1. Generate CSR on controller
2. Sign CSR on the private CA
3. Install signed CSR back on controller
4. Install root-chain of your private CA on controller
You will need to repeat this for vBond, vSmart and vManage.
Hope this helps.
David
09-02-2018 03:02 AM
Thanks David, i downloaded XCA, generated CSR from Vmanage, imported the CSR in XCA, went to Certificates in XCA->New Certificate->Selected the imported CSR->selected "create a self signed certificate" but it gave error:
"The Key you selected for signing is not a private one"
where do i get this private key?
09-04-2018 06:26 PM
You need to create a working XCA setup before you import any CSRs... Please refer to some online documentation. XCA is just one tool, there are others as well.
09-10-2018 05:04 AM
XCA is pretty easy to use but it complains about private key. I just want to know where we create the CSR from VManage where does it store the private key?
09-10-2018 12:04 PM
PKI is a private/public key system. Private key is stored on vManage. Public key is used in the CSR that XCA will sign. You do not need vManage private key for XCA.
09-10-2018 04:54 PM
Hi,
I did get the CSR signed and got the certificate when i installed it on vmanage it gave this error:
"Error: root-ca-chain unable to validate the certificate...Aborting!"
Thanks,
Aamir
09-10-2018 05:25 PM
Great! Now before you try to install the signed CSR back into vManage, you need to load the root chain from your XCA into vManage. The root cert is exportable from XCA. You need this command to install root chain into vManage.
09-16-2018 05:19 AM
Thanks David all is good now and Vmanage is up and has the certificate installed. Now i want to add Vbond and when i go to Vmanage->Controllers->Add Vbond, i put the management IP of vbond and it says:
Network is unreachable
Even though i can ping the Vbond mgmt Ip from vmanage, any tips here?
09-16-2018 10:16 AM
09-17-2018 02:19 AM
The IP which i configured on VPN 512 in Vbond. From Vmanage i can ping that IP.
11-14-2018 11:05 PM
Hi David,
I am also trying to setup SD-WAN lab and afterward will start customer PoC.
I have setup control n with vManage, vBond, vSmart with self signed certificate through vshell and viptela cli. I generated CSR from vEdge cloud VM and also signed from vManage like I did with vBond and vSmart.
I am using version 18.3.3 for all devices.
last step where I am stuck is to add vEdge cloud VM router into control plan. I not using Symantec or private CA but using vManag as self signed certificate.
plea let m now how could I add vEdge cloud?
if I use MS CA server then which certificate template I will use to sign certificate from CA.
Thanks,
Imran
11-17-2018 12:58 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide