06-03-2019 01:06 PM
In the Expressway Cluster Creation and Maintenance Deployment guide X8-11-4, regarding certificates; it reads:
We recommend populating the CN of all peer certificates with the same cluster FQDN, and populating each peer certificate's SAN with that peer's FQDN.
How do you populate the CN with the cluster FQDN?
When I generate a CSR, the CN is automatically filled in with the system FQDN, and can't be changed.
Solved! Go to Solution.
06-03-2019 09:55 PM
Hello,
If you have enabled clustering, and then you are generating the CSR on the top it will give you a drop down to put either CN as server system name or cluster FQDN.
But if the clustering is not enabled then probably you will not get this and will only get the CN as system name.
You can refer the below link-
Thanks.
Please rate if it is helpful....
06-03-2019 09:55 PM
Hello,
If you have enabled clustering, and then you are generating the CSR on the top it will give you a drop down to put either CN as server system name or cluster FQDN.
But if the clustering is not enabled then probably you will not get this and will only get the CN as system name.
You can refer the below link-
Thanks.
Please rate if it is helpful....
06-04-2019 04:36 AM
Thanks
I'll give that a try.
The recommendation I referenced is in the prerequisites section of the document, under Basic Configuration.
That's why I thought it was to be done before clustering is enabled.
On a side note: the link you sent goes to a Microsoft Azure on Cisco UCS video.
I'll see if I can find the one you referenced.
06-04-2019 05:35 AM
Hi,
on the same portal try to search video for " Generating CSR for MRA/ Clustered Expressways"
or try to copy paste the link on browser not sure why its giving different page-
Thanks.
Please rate if it is helpful and accept as a solution if its solves your issue...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide