Showing results for 
Search instead for 
Did you mean: 

Choose one of the topics below for SD-WAN Resources to help you on your journey with SD-WAN

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.


Enterprise CA CSR fields - what should be configured



I'm setting up a lab environment, and have everything working now with an openssl Enterprise CA, but came across an issue that I was not able to resolve.


If ANY changes are made in Administration->Settings->Controller Certificate Authorization->Enterprise Root Certificate->Set CSR Properties, any attempt to generate a CSR will fail.


This is on 19.1 release.


Is this simply a bug, or is there some special values that MUST be set in these CSR fields, and if so, what must they match in the Enterprise root CA chain values?


The Enterprise CA works, and all CSRs and certificates generated for the controllers have the following fixed values, which do not appear to be possible to change:

C = US,

ST = California,

L = San Jose,

O = Viptela LLC,

OU = ******, (my OU appears here)

CN = vmanage-****, (my chassis-num/unique-id appears here)

emailAddress =


Or is there something else that I'm missing...


Any assistance on this would be much appreciated, thanks in advance.

Everyone's tags (3)
CreatePlease to create content
Content for Community-Ad
August's Community Spotlight Awards