Users Guide

Table Of Contents
3. Click Generate.
A new CSR is generated. Save it to the management station.
Generating CSR Using RACADM
To generate a CSR using RACADM, use the objects in the cfgRacSecurity group with the config command or use
the objects in the iDRAC.Security group with the set command, and then use the sslcsrgen command to generate
the CSR. For more information, see the iDRAC8 RACADM Command Line Interface Reference Guide available at dell.com/
support/manuals.
Uploading Server Certificate
After generating a CSR, you can upload the signed SSL server certificate to the iDRAC firmware. iDRAC must be reset to apply
the certificate. iDRAC accepts only X509, Base 64 encoded Web server certificates. SHA-2 certificates are also supported.
CAUTION: During reset, iDRAC is not available for a few minutes.
Related concepts
SSL Server Certificates on page 82
Uploading Server Certificate Using Web Interface
To upload the SSL server certificate:
1. In the iDRAC Web interface, go to Overview > iDRAC Settings > Network > SSL, select Upload Server Certificate and
click Next.
The Certificate Upload page is displayed.
2. Under File Path, click Browse and select the certificate on the management station.
3. Click Apply.
The SSL server certificate is uploaded to iDRAC.
4. A pop-up message is displayed asking you to reset iDRAC immediately or at a later time. Click Reset iDRAC or Reset
iDRAC Later as required.
iDRAC resets and the new certificate is applied. The iDRAC is not available for a few minutes during the reset.
NOTE: You must reset iDRAC to apply the new certificate. Until iDRAC is reset, the existing certificate is active.
Uploading Server Certificate Using RACADM
To upload the SSL server certificate, use the sslcertupload command. For more information, see the RACADM Command
Line Reference Guide for iDRAC available at dell.com/support/manuals.
If the CSR is generated outside of iDRAC with a private key available, then to upload the certificate to iDRAC:
1. Send the CSR to a well-known root CA. CA signs the CSR and the CSR becomes a valid certificate.
2. Upload the private key using the remote racadm sslkeyupload command.
3. Upload the signed certificate to iDRAC using the remote racadm sslcertupload command.
The new certificate is uploaded iDRAC. A message is displayed asking you to reset iDRAC.
4. Run the racadm racreset command to reset iDRAC.
iDRAC resets and the new certificate is applied. The iDRAC is not available for a few minutes during the reset.
NOTE: You must reset iDRAC to apply the new certificate. Until iDRAC is reset, the existing certificate is active.
Viewing Server Certificate
You can view the SSL server certificate that is currently being used in iDRAC.
84
Configuring iDRAC