7.2

Table Of Contents
5 Select the certicate type from the  Action menu.
If you are using a PEM-encoded certicate, for example for a distributed environment, select Import.
Certicates that you import must be trusted and must also be applicable to all instances of vRealize
Automation appliance and any load balancer through the use of Subject Alternative Name (SAN)
certicates.
N If you use certicate chains, specify the certicates in the following order:
a Client/server certicate signed by the intermediate CA certicate
b One or more intermediate certicates
c A root CA certicate
Option Action
Keep Existing
Leave the current SSL conguration. Select this option to cancel your
changes.
Generate Certificate
a The value displayed in the Common Name text box is the Host Name
as it appears on the upper part of the page. If any additional instances
of the vRealize Automation appliance available, their FQDNs are
included in the SAN aribute of the certicate.
b Enter your organization name, such as your company name, in the
Organization text box.
c Enter your organizational unit, such as your department name or
location, in the Organizational Unit text box.
d
Enter a two-leer ISO 3166 country code, such as US, in the Country
text box.
Import
a Copy the certicate values from BEGIN PRIVATE KEY to END
PRIVATE KEY, including the header and footer, and paste them in the
RSA Private Key text box.
b Copy the certicate values from BEGIN CERTIFICATE to END
CERTIFICATE, including the header and footer, and paste them in the
 Chain text box. For multiple certicate values, include a
BEGIN CERTIFICATE header and END CERTIFICATE footer for each
certicate.
N In the case of chained certicates, additional aributes may be
available.
c (Optional) If your certicate uses a pass phrase to encrypt the
certicate key, copy the pass phrase and paste it in the Passphrase text
box.
6 Click Save  to save host information and SSL conguration.
7 If required by your network or load balancer, copy the imported or newly created certicate to the
virtual appliance load balancer.
You might need to enable root SSH access in order to export the certicate.
a If not already logged in, log in to the vRealize Automation appliance Management Console as root.
b Click the Admin tab.
c Click the Admin sub menu.
d Select the SSH service enabled check box.
Deselect the check box to disable SSH when nished.
Installing vRealize Automation
70 VMware, Inc.