7.4

Table Of Contents
Certificate Property Requirements
Hash Algorithm SHA1, SHA2, (256, 584, 512)
Signature Algorithm RSASSA-PKCS1_V!_5
Key Length 2084, 4096
Note The RSASSA-PSS signature is not supported for vRealize Automation deployments. This
signature is the default for a Microsoft CA on Windows 2012 R2. The signature is a configurable
parameter, so you must ensure that it is set appropriately when using a Microsoft CA.
vRealize Automation Certificate Support Matrix
Hash
Algorithm SHA1 SHA2-256
Signature
Algorithm
RSASSA-
PKCS1_V1_5
RSASSA-PSS RSASSA-PKCS1_V1_5 RSASSA-PSS
Key Size 2048 4096 2048 4096 2048 4096 2048 4096
vRealize
Automation
Supported
Supporte
d Verified
Supporte
d Verified
Not
Supported
Not
Supported
Supported
Verified
Supported
Verified
Not
Supported
Not
Supported
Hash
Algorithm SHA2-384 SHA2-512
Signature
Algorithm
RSASSA-PKCS1_V1_5 RSASSA-PSS RSASSA-PKCS1_V1_5 RSASSA-PSS
Key Size 2048 4096 2048 4096 2048 4096 2048 4096
vRealize
Automation
Supported
Supported
Verified
Supported
Verified
Not
Supported
Not
Supported
Supported
Verified
Supported
Verified
Not
Supported
Not
Supported
Extracting Certificates and Private Keys
Certificates that you use with the virtual appliances must be in the PEM file format.
The examples in the following table use Gnu openssl commands to extract the certificate information you
need to configure the virtual appliances.
Installing vRealize Automation
VMware, Inc. 33