Replace the self-signed certificates with signed certificates from the Microsoft Certificate Authority by using SDDC Manager.

Procedure

  1. In the navigation pane, click Inventory > Workload Domains.
  2. On the Workload Domains page, click View Details.
  3. Click a workload domain name and then click the Security tab.
  4. Generate CSR files for the target components.
    1. From the table, select the check box for the resource type for which you want to generate a CSR.
    2. Click Generate CSR.
    3. Configure the settings and click Generate CSR.

      Option

      Description

      Algorithm

      Select the key algorithm for the certificate.

      Key Size

      Select the key size (2048 bit, 3072 bit, or 4096 bit) from the drop-down menu.

      Email

      Optionally, enter a contact email address.

      Organizational Unit

      Use this field to differentiate between divisions within your organization with which this certificate is associated.

      Organization

      Type the name under which your company is known. The listed organization must be the legal registrant of the domain name in the certificate request.

      Locality

      Type the city or locality where your company is legally registered.

      State

      Type the full name (do not abbreviate) of the state, province, region, or territory where your company is legally registered.

      Country

      Type the country name where your company is legally registered. This value must use the ISO 3166 country code.

  5. Generate signed certificates for each component.
    1. From the table, select the check box for the resource type for which you want to generate a signed certificate for.
    2. Click Generate Signed Certificates.
    3. In the Generate Certificates dialog box, from the Select Certificate Authority drop-down menu, select Microsoft.
    4. Click Generate Certificates.
  6. Install the generated signed certificates for each component.
    1. From the table, select the check box for the resource type for which you want to install a signed certificate.
    2. Click Install Certificates.