You can generate a certificate signing request (CSR) and get it signed by a certification authority (CA). If you generate a CSR at the global level, it is available to all NSX Edges in your inventory.

Procedure

  1. Do one of the following:
    • Generate a global certificate signing request for the NSX Manager.
      1. Log in to the NSX Manager virtual appliance.
      2. Click Manage Appliance Settings, and then click SSL Certificates.
      3. Click Generate CSR.
    • Generate a certificate signing request for an NSX Edge.
      1. Log in to the vSphere Web Client.
      2. Navigate to Networking & Security > NSX Edges.
      3. Double-click an NSX Edge.
      4. Click Manage > Settings > Certificates.
      5. Click CSR Actions or Actions, and then click Generate CSR.
  2. Type your organization unit and name.
  3. Type the locality, street, state, and country of your organization.
  4. Select the encryption algorithm for communication between the hosts.
    Attention: SSL VPN-Plus only supports RSA certificates.
  5. Edit the default key size, if necessary.
  6. Type a description for the certificate.
  7. Click OK.
    The CSR is generated and displayed in the Certificates list.
  8. Have an online Certification Authority sign this CSR.
  9. Do one of the following:
    • Import certificate at the global level in the NSX Manager virtual appliance.
      1. Click the Manage Appliance Settings, and then click SSL Certificates.
      2. Click Import.
      3. In the Import SSL Certificate dialog box, click Choose File, and browse to the signed certificate file.
      4. Click Import.
    • Import certificate for the NSX Edge.
      1. Copy the contents of the signed certificate that you received from the certification authority.
      2. In the vSphere Web Client, double-click the NSX Edge.
      3. Click CSR Actions or Actions, and then click Import Certificate.
      4. In the Import Certificate dialog box, paste the contents of the signed certificate.
      5. Click OK.
    The CA-signed certificate appears in the certificates list.