Generating CSR certificate using VCF Fleet Manager marks IP address as DNS when entering in IP address in the SAN
book
Article ID: 421072
calendar_today
Updated On:
Products
VCF Operations
Issue/Introduction
Generating CSR certificate succeeds, however VCF Fleet Manager classifies IP address as DNS in the SAN field instead of expected IP address when analyzing the certificate using a certificate decoder. The following documentation can be used as a guide to generating the CSR certificate Replace a Certificate with a CA-Signed Certificate
Environment
VCF Fleet Manager 9.0.x
Cause
VCF Fleet Manager 9.0.x does not have the option to specify IP address in the SAN field in the UI
Select private-internal-API from the drop down box
Navigate to the Locker Certificates Controller API → Post /lcm/locker/api/certificates/csr → Try it out → Fill in the required details, here you can specify IP. Tenant field is not required and the for the Host value please add your DNS entries
Additional Information
Changes will be made in later versions of VCF Fleet Manager to allow IP addresses to be specified separately.