cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
670
Views
5
Helpful
3
Replies

Apply internal signed certificate to CIMC/KVM sessions

joeharb
Level 5
Level 5

We have deployed an internal signed certificate for our UCS Fabrics and this is working as expected.  Is it possible to deploy an internal signed certificate to the management address of the blades themselves.  Our quarterly scans reveal that these are self signed and I am not sure this will pass the audit in the future.

Please advise,

Joe

3 Replies 3

Kirk J
Cisco Employee
Cisco Employee

Greetings.

The CIMC has an internal certificate that gets generated/re-generated when IPs change on the CIMC.

The IPs have the potential to change during decom/re-acks of the blades.

The certificates are generated with the IP in subjectName/Subject Alternate name and there is no DNS or hostname entry mapping available.  The certificates for the individual CIMCs are not user changeable.

Thanks,

Kirk...

Pom Ham
Cisco Employee
Cisco Employee

For the m5 series, 3.2(2x) has the enhancement to add self-signed cert to the cimc. For the m4 and m3 blades, it requires 4.0 our latest firmware.

Please see the bug below.

 

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCva19420/?reffering_site=dumpcr

 

 

Review Cisco Networking products for a $25 gift card