Configuring Custom Certificates for Management Center UI

book

Article ID: 168983

calendar_today

Updated On:

Products

Management Center

Issue/Introduction

Configuring Custom Certificates for Management Center UI

Resolution

For Management Center Versions 1.11.x and earlier

There is a requirement that is needed when generating a certificate to use for the Management Center GUI.  

  • The Private Key must be exportable.

After the certificate is generated, two more requirements must be met.

  • The cert must be in a PKCS12 format as this contains both the public and private keys
  • The Management Center servers must be restarted after the import is complete.

NOTE: The following example uses a Microsoft CA for generating the certificate. This example is a general guideline. The steps may differ depending on the CA version and other factors.

How to request a certificate from a Microsoft CA:

  1. When requesting a certificate on Microsoft CA the first task is to select Request a certificate.
  2. Next, select advanced certificate request.
  3. In the advanced certificate request, Create and submit a request to this CA.
  4. In the advanced certificate request, create a new certificate template and mark keys as exportable.  Please see Microsoft Documentation if this options is grayed out. 
  5. From here the Name field corresponds to the CN or Common Name field.  
  6. The Department field corresponds to the OU or Organizational Unit field.  
  7. Make sure to select the key as exportable as this is important.  
  8. The rest of the options can be left at the default settings.
  9. When exporting the certificate to a file, make sure to select export the private key.  
  10. It should select exporting out the key in PCKS #12 format at this time.
  11. Do not select Export all extended properties in the options.
  12. Do not select Include all certificates in the certification path if possible option
  13. Put this certificate file where it can be downloaded via SCP/FTP/FTPS/HTTP/HTTPS, as these are the methods to download the certificate onto the Management Center.

 

How to import Certificate into Management Center:

  1. Login to the Management Center CLI and enter enable mode.
  2. To import the new cert that was generated, run the command security ssl import server-certificate <url>. Again you can use SCP/FTP/FTPS/HTTP/HTTPS for the URL.
  3. After the import is successful, the management services will need to be restarted.  Enter the command restart services, but note that this will log out all users because this is restarting the GUI services.

 

To reset the certificate back to a self signed certificate:

  1. Login to CLI of Management Center and enter enable mode.
  2. Run the command ssl delete server-certificate. This will delete any certificate that was imported.
  3. Generate a new self signed certificate by running the command security ssl generate-ssl-certificate.
  4. The Management Center services will need to be restarted again.  Enter the command restart services.

For Management Center Version 2.0.1.1 and later

Create New Certificate Signing Request (CSR) On Management Center Default Keyring, signed by External Authority

Noting that the process creates new CSR on the dafult Certificate Used by Management Center then replaces the Cert that way.

  1. Ceate CSR
    • #ssl create signing-request default subject C=CA,ST=ON,O=symc,CN=<MChostname/FQDN>
  2. View CSR
    • #ssl view signing-request default
  3. Copy out CSR
    • -----BEGIN CERTIFICATE REQUEST-----
      MIIEhTCCAm0CAQEwQDELMAkGA1UEBhMCQ0ExCzAJBgNVBAgTAk9OMQ0wCwYDVQQK
      EwRzeW1jMRUwEwYDVQQDEwwxMC4xNjkuMTAzLjYwggIiMA0GCSqGSIb3DQEBAQUA
      A4ICDwAwggIKAoICAQDAlFAmAT6AAsuN7ZUrgdHU5hFuB2lvBIbg8NOJCbCrR+dA
      z/pFogRUHMOQQ1dlQ4IHrC5i22RTemump/Nm9OEv9mU3AYjj/G3NRc4Uv9KWc569
      f9W0oVWQL3d+BL1CUQsvRknp0hy0HEynWlQo2X4gQeS8s0ExxLIAzpuM8mbsB6Jw
      DKBGbn8KdSM7lOms5FvPr3CUmY17ONpIV4HOCkSdvHdU9vl4O0M8xPJMNoP3bEU3
      RT+rrMtFloV3SxkT/m22cUDOhJ73iEcgfto788DQRE6YEJ5iFq3AcdAUHahyTQw1
      5KRUol+HS37d6+O0b+OFk5fXc/wMPLTlhRwOIAsfACBsTwjfati9zNc13gfnbb7h
      CifbRo30YcrLUmtB8n85wRBrnTWhnirkyi07Q4hZYifTdp8ZWvvvXN26SZoSn2Lm
      Ldu0ah9aqWisY86GAMAt3n+qSUrR15w1kcF18G18wST2bHprMzomcaKbyR3N5iBg
      2891pTecc/m4dkWNgawfUjBpAdGE12ycjbhBuRMkVEpMyrn/7ih39Gd6DskG1xGJ
      rGYoJuAyBYkIBgWtCNNpJssXxDYoHiuECC8StPDQQ0moXOrG8Vmkm4edZztPNwoT
      B2D/q/aUu9YqeRalJY4j7AL7LGiAmGhzmLawp8ek6YXlaUp6Z28OzScTK1VfyQID
      AQABoAAwDQYJKoZIhvcNAQELBQADggIBAHS0O6WmE9s+uoOllMJe5yhNkafagExq
      6B+L+ZXyBDHN7UA+FEtkyFv6M2ahF9znpCfMRKtz4n0YUUarIFpIhnX4O+U5rHz7
      c1TVSPm9nka97XhEDALhZHI9alLKqPGzH2l+1BqqnpqzS83M3NVuWzQWnMCatO5q
      QuSOu/SCvm+UbW71/bYPx86eU0lz56J5wRwxvcuRZqJ19Bo0zBNLsrRhUXy5wcBv
      ompT8fYHvtPxHOHRTtkFCT2d2zVeL4QTvMiKKrZYMp6+q2CG4h5PFQfg3ct+++f2
      sD4NcFq1P9IlsNfe2JREDLTUHzx6DPMR9Wkr2/qyxCya06ma21QhxHSjhD1zC7os
      3+7p/Mxi9F1gLTAWDBjpzpUUL3yGa6BrqhEAJLBB5nAMTOMuVQ7gbOgfThZ/zbiC
      3lBSyhU99J87Kw9djWZO3gPGd/LYShbneWR4FiMjDKvnmo5XdtTvE4jcM9I3NZeE
      pfQM92SThNjytSAEEZxhhtlRyiZ3zWioVeTEKsTFOkeo8OU2MApAh7qJLgLAzwje
      nT1UunaxAJL2UoYUgGBM6ImNvvYt0QRPeqxkM7vECMorisbxoRBGwaH7IF4+YZ1w
      +EPttgmg3QphrUp9VqrDuFJxJ9mqNTJwi3aFC7mKnhjsxA06OYUI48XYXGFirIGx
      AQgFtmD2WIn8
      -----END CERTIFICATE REQUEST-----
  4. Sign CSR with PKI Authority (Microsoft PKI Interanl Used here)
  5. Import Signed Certificate
    • #ssl inline certificate default
    • Enter the certificate below and end it with a Ctrl-D
      -----BEGIN CERTIFICATE-----
      MIIHrzCCBZegAwIBAgIKIgWPNgAAAAAAGjANBgkqhkiG9w0BAQsFADBFMRMwEQYK
      CZImiZPyLGQBGRYDbGFiMRYwFAYKCZImiZPyLGQBGRYGZHJhcGVyMRYwFAYDVQQD
      Ew1kcmFwZXItbGFiLUNBMB4XDTE4MDYyMDIzNDYyNVoXDTIwMDYxOTIzNDYyNVow
      QDELMAkGA1UEBhMCQ0ExCzAJBgNVBAgTAk9OMQ0wCwYDVQQKEwRzeW1jMRUwEwYD
      VQQDEwwxMC4xNjkuMTAzLjYwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoIC
      AQDAlFAmAT6AAsuN7ZUrgdHU5hFuB2lvBIbg8NOJCbCrR+dAz/pFogRUHMOQQ1dl
      Q4IHrC5i22RTemump/Nm9OEv9mU3AYjj/G3NRc4Uv9KWc569f9W0oVWQL3d+BL1C
      UQsvRknp0hy0HEynWlQo2X4gQeS8s0ExxLIAzpuM8mbsB6JwDKBGbn8KdSM7lOms
      5FvPr3CUmY17ONpIV4HOCkSdvHdU9vl4O0M8xPJMNoP3bEU3RT+rrMtFloV3SxkT
      /m22cUDOhJ73iEcgfto788DQRE6YEJ5iFq3AcdAUHahyTQw15KRUol+HS37d6+O0
      b+OFk5fXc/wMPLTlhRwOIAsfACBsTwjfati9zNc13gfnbb7hCifbRo30YcrLUmtB
      8n85wRBrnTWhnirkyi07Q4hZYifTdp8ZWvvvXN26SZoSn2LmLdu0ah9aqWisY86G
      AMAt3n+qSUrR15w1kcF18G18wST2bHprMzomcaKbyR3N5iBg2891pTecc/m4dkWN
      gawfUjBpAdGE12ycjbhBuRMkVEpMyrn/7ih39Gd6DskG1xGJrGYoJuAyBYkIBgWt
      CNNpJssXxDYoHiuECC8StPDQQ0moXOrG8Vmkm4edZztPNwoTB2D/q/aUu9YqeRal
      JY4j7AL7LGiAmGhzmLawp8ek6YXlaUp6Z28OzScTK1VfyQIDAQABo4ICpDCCAqAw
      HQYDVR0OBBYEFJgVI9wQ9Ftw1PRLV0gtxnp/HPkuMB8GA1UdIwQYMBaAFKIFFArl
      UOKfEmqN2YsEo43w+U61MIH+BgNVHR8EgfYwgfMwgfCgge2ggeqGgbFsZGFwOi8v
      L0NOPWRyYXBlci1sYWItQ0EsQ049dm02ODYsQ049Q0RQLENOPVB1YmxpYyUyMEtl
      eSUyMFNlcnZpY2VzLENOPVNlcnZpY2VzLENOPUNvbmZpZ3VyYXRpb24sREM9ZHJh
      cGVyLERDPWxhYj9jZXJ0aWZpY2F0ZVJldm9jYXRpb25MaXN0P2Jhc2U/b2JqZWN0
      Q2xhc3M9Y1JMRGlzdHJpYnV0aW9uUG9pbnSGNGh0dHA6Ly92bTY4Ni5kcmFwZXIu
      bGFiL0NlcnRFbnJvbGwvZHJhcGVyLWxhYi1DQS5jcmwwggETBggrBgEFBQcBAQSC
      AQUwggEBMIGrBggrBgEFBQcwAoaBnmxkYXA6Ly8vQ049ZHJhcGVyLWxhYi1DQSxD
      Tj1BSUEsQ049UHVibGljJTIwS2V5JTIwU2VydmljZXMsQ049U2VydmljZXMsQ049
      Q29uZmlndXJhdGlvbixEQz1kcmFwZXIsREM9bGFiP2NBQ2VydGlmaWNhdGU/YmFz
      ZT9vYmplY3RDbGFzcz1jZXJ0aWZpY2F0aW9uQXV0aG9yaXR5MFEGCCsGAQUFBzAC
      hkVodHRwOi8vdm02ODYuZHJhcGVyLmxhYi9DZXJ0RW5yb2xsL3ZtNjg2LmRyYXBl
      ci5sYWJfZHJhcGVyLWxhYi1DQS5jcnQwIQYJKwYBBAGCNxQCBBQeEgBXAGUAYgBT
      AGUAcgB2AGUAcjAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEw
      DQYJKoZIhvcNAQELBQADggIBAL2rjd+GMaV3XROVwnsxzU09fhq9RQKUL1Yq9wRW
      05Jw2/Jk5CnEhSPeMf4yjC2oVsoen+TutVPN6PeWjG3Q7XGA7+/x3i55yyQg803J
      yKk0O2xDouzdxPpw2ezETBEPQvjZfu8suphxBy6tz8NvVwYCUolQDXfZ1xwuZ+RJ
      Lze5Kxhqg8LwCg9ncvhkTheZXrQiuIi/FkS6/zBW5oTWPI3nS9yNAnNPCdkgO/qO
      THAYCWZU1nLA9PKy3MT0B51gw8KnldBGlUgFTkyedxaD7G0WIgNzK5bg86SpEz2b
      L7cen4N8xChiQSdoVX6714arAOPd9o4TZiOygKGpAarfJdHUwPuDmBsQrrRpmdzR
      IbMFVDyXeZtJ+YMjdl0uZ1OuNlkAW0rs7f+L1ymCCyYUbr6D3qkeqB98yrprZVbo
      u48dk/xjcNbo5tOp/F7XuCDgbPi4OL4nsXX6CVqssqQdZ900+DyM2fjyQsi9Bg8c
      iHJl3oXPlVf9V+IYhkrxgT8iDSXR4gngn1WPIcDqRm3xlxy5REmN9COKwUPQ3aUW
      /TofI56Cq1nx2q1W6YxIjgahGwNG1/XI6ZRt0mCUzph5MzSjlxEekH3l+6ZlFKTd
      NWUzibSECMAectDAXKutp0kEfFJ+PjDFacdQUHOy+hqabDaWygTDtlqMwfbgmA5h
      QMWl
      -----END CERTIFICATE-----

    •   A certificate already exists for keyring default. Would you like to replace it? (yes/no) [no]: yes
        ok

  6. # system-services restart management-center

Import complete Externally signed Private key and Certificate to replace the Default

  1. Install the External Private Key into the Default Keyring

    • (config)# ssl inline keyring default

      Enter the keyring below and end it with a Ctrl-D
      -----BEGIN PRIVATE KEY-----
      MIIJQwIBADANBgkqhkiG9w0BAQEFAASCCS0wggkpAgEAAoICAQDAlFAmAT6AAsuN
      7ZUrgdHU5hFuB2lvBIbg8NOJCbCrR+dAz/pFogRUHMOQQ1dlQ4IHrC5i22RTemum
      p/Nm9OEv9mU3AYjj/G3NRc4Uv9KWc569f9W0oVWQL3d+BL1CUQsvRknp0hy0HEyn
      WlQo2X4gQeS8s0ExxLIAzpuM8mbsB6JwDKBGbn8KdSM7lOms5FvPr3CUmY17ONpI
      V4HOCkSdvHdU9vl4O0M8xPJMNoP3bEU3RT+rrMtFloV3SxkT/m22cUDOhJ73iEcg
      fto788DQRE6YEJ5iFq3AcdAUHahyTQw15KRUol+HS37d6+O0b+OFk5fXc/wMPLTl
      hRwOIAsfACBsTwjfati9zNc13gfnbb7hCifbRo30YcrLUmtB8n85wRBrnTWhnirk
      yi07Q4hZYifTdp8ZWvvvXN26SZoSn2LmLdu0ah9aqWisY86GAMAt3n+qSUrR15w1
      kcF18G18wST2bHprMzomcaKbyR3N5iBg2891pTecc/m4dkWNgawfUjBpAdGE12yc
      jbhBuRMkVEpMyrn/7ih39Gd6DskG1xGJrGYoJuAyBYkIBgWtCNNpJssXxDYoHiuE
      CC8StPDQQ0moXOrG8Vmkm4edZztPNwoTB2D/q/aUu9YqeRalJY4j7AL7LGiAmGhz
      mLawp8ek6YXlaUp6Z28OzScTK1VfyQIDAQABAoICADN/9icTshkdpj3gSUIHR4v9
      sq+P/9wWg9Nn08oT81D6u5cTh0RT3YB46LuNprOH6CARJZ5+OUgxttQsmeTwm7/t
      zod1O5xshxicEE5wNerSJKNcqlPRyUXzy6rBrbMsZSdRTrbe35oy7zTZ7SO3dgk+
      VeM4tLiQd2HL3sFEmc2JBSGd3sa3CfZL+Q4X9p2ru/nAWwUCQ1mujIFIFYh6Kntc
      STVJjtFeV87KhFlpQsVKCQCM3kgUv49uf2a1iJFWOxTNGJ2hzbk4knzYL5hUyT1o
      5vO3jgOBORn71b9rZv6aKCfJa0DO42kVAWpriMtaGKhCHhsaA09qdJ3kiOomG5LJ
      ku22locfwjlk+e0uHWxBg/cBVujL15LXo997iQWcar7+4N9TUOV7NBUIB9ZbxJw1
      /ZFQ+2s/8Eqzmt/e7d69jJGiIAGimmjsQPvb8xmtzXJKaN/43If7do28Cs97Yg4i
      QKRVt58iE5FR7qPpYJBMJZYNecgFXptlR7d8Hlempgi/m/jaQGVKv50orMtQAGbr
      h6HMKswaM+r4BDL9TdJlduOX+/J9T0YtQBH+JM5EcT4TNHJo5QjBpU78KpvYQB5N
      lvpFRMsKaNUtRfmXtcEOS3ia3g4GgAhuGuqzRtp/pLR0VN9IbyHwoyNbFsV1lZ3c
      K7l+5f6WE/RYC/zGLJYBAoIBAQDxfRkq6W+oAWMPF2R1okqhkXfk8EiFKKemefJd
      F/Y+21JvJeHyWmEZWZhMBiQZWe7Z11s6fVAfjeWtjI0RJyEzPrgO9YgTGHsrnKZQ
      Nqd3sJStXTtsly71WtKbmxZ0m05PtdtqQ16sN1DdV3S0ZP0bqGlUrqqo7W0d02gu
      XDO6WYOmqwoFnR1QHVcRt2TFBlJ0w9UizU4J8UTx8DFq+PQQdhIyP4iJoPesykGr
      aF3ZYJPIi4YVKbtcEA8y4tAxuBysZTWFYBbsRrF2Kp4nY5t5oQjeMtVr9h8BwIRQ
      SHP+zSF9juxpKM5mtfdm+e1wrCEky3fn6sVGzVo6By7iG4uhAoIBAQDMJtODahxw
      d88GCLQ5AODLH1nvaBhlt7OiTGP+wQj03otNXFn84qkhux9ErTSASg16WniMV5gp
      lkF8DZzoUcpQT4uYMyeoJxpJ+SDLIQ/7J0KawR3Tucm8+IoKcgskCl3Sw0p5yZoS
      hpFfW919xIF+krHO8BnYheL5NFqu827MSyraDEX5liGLgNG8PrzsZnacRGVQCn0s
      3rGX/nhh5Q2diw/1ykWeGP6gSTrTdcbxhcke/jHBZyN68Q7bDxYJZpaVnhMiV7SA
      TKco0qhI4RGLY4FRmj4qaXg8vOpIc0+zolzkKlPr93ln7m6MU8oiO6/p3W5Bfai9
      YnsNhnp4tSMpAoIBAQDmjHBCr6qR0wEnn0WhqNdneOHmCCC0QCQOo83nYsENMYZ5
      5sjX/8FD2m2z5wj/ywRlpVzLcmfUODxWfCERhzIDIpXGclL/KBgvgtalLgikFEld
      We0ptwx14cfAF0hQ+xTAtPZNdRQlhooFR0F8GA4tIZOt7TOxIztRhkuoNw6LknpF
      3HUs9trNabV+jIAAOhDuuSf6mdcvVtBjytTjM9qO/KpSnqVUAAF1TYN0iadPqQxu
      IgZYngbp1css4a2ySfvV+qomM56u5K74CagEIuyEKmG1AQMQl2Dy40FvBDz5vg2D
      ObgqjXLATGluPp2ZPDxITJilKVY+Sj8ht0njRDkBAoIBAAtLkqRQuKYYWuHwlVga
      DlXutCEk10S5dzzhkR7FO2Og9IAhPfFZ8RWmrsIz+xWmAzzjyIurRQX4BEOC1U2d
      SN5MqGKRYf5Ru4igOgpDGAlDUNITIT1XqCvGbIzLZoZl9G720yYN23Ju85gdExIk
      Ty3bm+7hJezu63HyTZokadrvxb0utKhsgAqh4/jQV8+Uk7dtqVVWXzqeT6EjOTHh
      ZHF1AjsNJ/DpXR0tMA4HFCzExC3szn/u3u2sbK/+E7ANdwNsLY7W32vB0fXWQe1W
      Vowpwzvqlsnt7/McWLINfzlnIFCXbvE9TgBMFt24vRRLzR3ZXIJPG4ju6/QBnsES
      9JECggEBAJOn6tDkpSjPR335sl5xLFalw5GGVUyRJsMoI/PwzfSlzxe8nf5NOnUG
      dJnWjUTdg9fgBZQVLErNEc/DDNRocc6lJmqUhSYuQanSp+Jq8SKZAlT0x2UZjxLQ
      1EhkdcVelxC+XHBwAfMTVpjMhqU/EYdfHPRTy2F/BgVf1msbCVK4QIqt1g+f5i82
      36fvg8lABwmWd/h6pDNwv2H9ZfO00znZbkcUdgk+qyFARZaHDX8KhsyzrgZwWSd1
      fBY0pY5JeXm/x8jOoNpeZ0oCEXq2+qgJY+Dy/waJIgqJ1EVgTBqxcLdGPwJb4OYx
      s3DcFoFJRM3DNygSI6zekORaU7UEMfY=
      -----END PRIVATE KEY-----

        ok

  2. Install the External Certificate into the Default Keyring

    • (config)# ssl inline certificate default
      Enter the certificate below and end it with a Ctrl-D
      -----BEGIN CERTIFICATE-----
      MIIHrzCCBZegAwIBAgIKIgWPNgAAAAAAGjANBgkqhkiG9w0BAQsFADBFMRMwEQYK
      CZImiZPyLGQBGRYDbGFiMRYwFAYKCZImiZPyLGQBGRYGZHJhcGVyMRYwFAYDVQQD
      Ew1kcmFwZXItbGFiLUNBMB4XDTE4MDYyMDIzNDYyNVoXDTIwMDYxOTIzNDYyNVow
      QDELMAkGA1UEBhMCQ0ExCzAJBgNVBAgTAk9OMQ0wCwYDVQQKEwRzeW1jMRUwEwYD
      VQQDEwwxMC4xNjkuMTAzLjYwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoIC
      AQDAlFAmAT6AAsuN7ZUrgdHU5hFuB2lvBIbg8NOJCbCrR+dAz/pFogRUHMOQQ1dl
      Q4IHrC5i22RTemump/Nm9OEv9mU3AYjj/G3NRc4Uv9KWc569f9W0oVWQL3d+BL1C
      UQsvRknp0hy0HEynWlQo2X4gQeS8s0ExxLIAzpuM8mbsB6JwDKBGbn8KdSM7lOms
      5FvPr3CUmY17ONpIV4HOCkSdvHdU9vl4O0M8xPJMNoP3bEU3RT+rrMtFloV3SxkT
      /m22cUDOhJ73iEcgfto788DQRE6YEJ5iFq3AcdAUHahyTQw15KRUol+HS37d6+O0
      b+OFk5fXc/wMPLTlhRwOIAsfACBsTwjfati9zNc13gfnbb7hCifbRo30YcrLUmtB
      8n85wRBrnTWhnirkyi07Q4hZYifTdp8ZWvvvXN26SZoSn2LmLdu0ah9aqWisY86G
      AMAt3n+qSUrR15w1kcF18G18wST2bHprMzomcaKbyR3N5iBg2891pTecc/m4dkWN
      gawfUjBpAdGE12ycjbhBuRMkVEpMyrn/7ih39Gd6DskG1xGJrGYoJuAyBYkIBgWt
      CNNpJssXxDYoHiuECC8StPDQQ0moXOrG8Vmkm4edZztPNwoTB2D/q/aUu9YqeRal
      JY4j7AL7LGiAmGhzmLawp8ek6YXlaUp6Z28OzScTK1VfyQIDAQABo4ICpDCCAqAw
      HQYDVR0OBBYEFJgVI9wQ9Ftw1PRLV0gtxnp/HPkuMB8GA1UdIwQYMBaAFKIFFArl
      UOKfEmqN2YsEo43w+U61MIH+BgNVHR8EgfYwgfMwgfCgge2ggeqGgbFsZGFwOi8v
      L0NOPWRyYXBlci1sYWItQ0EsQ049dm02ODYsQ049Q0RQLENOPVB1YmxpYyUyMEtl
      eSUyMFNlcnZpY2VzLENOPVNlcnZpY2VzLENOPUNvbmZpZ3VyYXRpb24sREM9ZHJh
      cGVyLERDPWxhYj9jZXJ0aWZpY2F0ZVJldm9jYXRpb25MaXN0P2Jhc2U/b2JqZWN0
      Q2xhc3M9Y1JMRGlzdHJpYnV0aW9uUG9pbnSGNGh0dHA6Ly92bTY4Ni5kcmFwZXIu
      bGFiL0NlcnRFbnJvbGwvZHJhcGVyLWxhYi1DQS5jcmwwggETBggrBgEFBQcBAQSC
      AQUwggEBMIGrBggrBgEFBQcwAoaBnmxkYXA6Ly8vQ049ZHJhcGVyLWxhYi1DQSxD
      Tj1BSUEsQ049UHVibGljJTIwS2V5JTIwU2VydmljZXMsQ049U2VydmljZXMsQ049
      Q29uZmlndXJhdGlvbixEQz1kcmFwZXIsREM9bGFiP2NBQ2VydGlmaWNhdGU/YmFz
      ZT9vYmplY3RDbGFzcz1jZXJ0aWZpY2F0aW9uQXV0aG9yaXR5MFEGCCsGAQUFBzAC
      hkVodHRwOi8vdm02ODYuZHJhcGVyLmxhYi9DZXJ0RW5yb2xsL3ZtNjg2LmRyYXBl
      ci5sYWJfZHJhcGVyLWxhYi1DQS5jcnQwIQYJKwYBBAGCNxQCBBQeEgBXAGUAYgBT
      AGUAcgB2AGUAcjAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEw
      DQYJKoZIhvcNAQELBQADggIBAL2rjd+GMaV3XROVwnsxzU09fhq9RQKUL1Yq9wRW
      05Jw2/Jk5CnEhSPeMf4yjC2oVsoen+TutVPN6PeWjG3Q7XGA7+/x3i55yyQg803J
      yKk0O2xDouzdxPpw2ezETBEPQvjZfu8suphxBy6tz8NvVwYCUolQDXfZ1xwuZ+RJ
      Lze5Kxhqg8LwCg9ncvhkTheZXrQiuIi/FkS6/zBW5oTWPI3nS9yNAnNPCdkgO/qO
      THAYCWZU1nLA9PKy3MT0B51gw8KnldBGlUgFTkyedxaD7G0WIgNzK5bg86SpEz2b
      L7cen4N8xChiQSdoVX6714arAOPd9o4TZiOygKGpAarfJdHUwPuDmBsQrrRpmdzR
      IbMFVDyXeZtJ+YMjdl0uZ1OuNlkAW0rs7f+L1ymCCyYUbr6D3qkeqB98yrprZVbo
      u48dk/xjcNbo5tOp/F7XuCDgbPi4OL4nsXX6CVqssqQdZ900+DyM2fjyQsi9Bg8c
      iHJl3oXPlVf9V+IYhkrxgT8iDSXR4gngn1WPIcDqRm3xlxy5REmN9COKwUPQ3aUW
      /TofI56Cq1nx2q1W6YxIjgahGwNG1/XI6ZRt0mCUzph5MzSjlxEekH3l+6ZlFKTd
      NWUzibSECMAectDAXKutp0kEfFJ+PjDFacdQUHOy+hqabDaWygTDtlqMwfbgmA5h
      QMWl
      -----END CERTIFICATE-----

      A certificate already exists for keyring default. Would you like to replace it? (yes/no) [no]: yes
        ok

  3. # system-services restart management-center

Regenerate/Renew the default self signed for export from browser:

  • (config)# ssl regenerate certificate default subject C=CA,ST=ON,O=symc,CN=10.169.103.6
    A certificate already exists for keyring default. Would you like to replace it? (yes/no) [no]: yes
      ok
     
  •   Export through the browser connection viewing Certificate Path

Attachments

MC_CLI_Reference_Guide_2.0.1.1.pdf get_app