7.4

Table Of Contents
Table 29. Certificate Implementations
Component
Minimal Deployment (non-
production) Distributed Deployment (production-ready)
vRealize
Automation
Appliance
Generate a self-signed certificate
during appliance configuration.
For each appliance cluster, you can use a certificate from an
internal or external certificate authority. Multi-use and wildcard
certificates are supported.
IaaS Components During installation, accept the
generated self-signed certificates or
select certificate suppression.
Obtain a multi-use certificate, such as a Subject Alternative Name
(SAN) certificate, from an internal or external certificate authority
that your Web client trusts.
Certificate Chains
If you use certificate chains, specify the certificates in the following order.
n
Client/server certificate signed by the intermediate CA certificate
n
One or more intermediate certificates
n
A root CA certificate
Include the BEGIN CERTIFICATE header and END CERTIFICATE footer for each certificate when you
import certificates.
Certificate Changes if Customizing the vRealize Automation Login
URL
If you want users to log in to a URL name other than a vRealize Automation appliance or load balancer
name, see the pre and post installation CNAME steps in Set the vRealize Automation Login URL to a
Custom Name.
vRealize Automation Certificate Requirements
When using your own certificates with vRealize Automation, the certificates need to meet certain
requirements.
Supported Certificate Types
In many organizations, certificates are issued or requested by external authorities according to company
requirements.
The following requirements address common identity format and certificate types used with typical
vRealize Automation deployments.
Installing vRealize Automation
VMware, Inc. 32