Users Guide

certicate authority issues a certicate to the applicant that uniquely identies that applicant for transactions over networks and on the
Internet.
After the certicate authority approves the CSR and sends you a certicate, you must upload the certicate to the CMC rmware. The
CSR information stored on the CMC rmware must match the information contained in the certicate.
NOTE: To congure SSL settings for CMC, you must have Chassis Conguration Administrator privilege.
NOTE: Any server certicate you upload must be current (not expired) and signed by a certicate authority.
Related links
Generating a New Certicate Signing Request
Uploading Server Certicate
Viewing Server Certicate
Generating a New Certicate Signing Request
To ensure security, it is strongly recommended that you obtain and upload a secure server certicate to CMC. Secure server certicates
ensure the identity of a remote system and that information exchanged with the remote system cannot be viewed or changed by others.
Without a secure server certicate, CMC is vulnerable to access from unauthorized users.
To obtain a secure server certicate for CMC, you must submit a Certicate Signing Request (CSR) to a certicate authority of your
choice. A CSR is a digital request for a signed, secure server certicate containing information about your organization and a unique,
identifying key.
After generating the CSR, you are prompted to save a copy to your management station or shared network, and the unique information
used to generate the CSR is stored on CMC. This information is used later to authenticate the server certicate you receive from the
certicate authority. After you receive the server certicate from the certicate authority, you must then upload it to CMC.
NOTE
: For CMC to accept the server certicate returned by the certicate authority, authentication information contained in
the new certicate must match the information that was stored on CMC when the CSR was generated.
CAUTION: When a new CSR is generated, it overwrites any previous CSR on CMC. If a pending CSR is overwritten before its
server certicate is granted from a certicate authority, CMC does not accept the server certicate because the information it
uses to authenticate the certicate has been lost. Take caution when generating a CSR to prevent overwriting any pending CSR.
Generating a New Certicate Signing Request Using Web Interface
To generate a CSR using the CMC Web interface:
1 In the system tree, go to Chassis Overview, and then click Network > SSL. The SSL Main Menu is displayed.
2 Select Generate a New Certicate Signing Request (CSR) and click Next. The Generate Certicate Signing Request (CSR) page
is displayed.
3 Type a value for each CSR attribute value.
4 Click Generate. A File Download dialog box appears.
5 Save the csr.txt le to your management station or shared network. (You may also open the le at this time and save it later.) You must
later submit this le to a certicate authority.
Generating CSR Using RACADM
To generate a CSR, use the objects in cfgRacSecurityData group to specify the values and use the sslcsrgen command to
generate the CSR. For more information, see the Chassis Management Controller for Dell PowerEdge M1000e RACADM Command Line
Reference Guide available at dell.com/support/manuals.
Conguring
CMC 95