Install Microsoft CA-Signed Certificates using
SDDC Manager
Replace the self-signed certificates with signed certificates from the Microsoft Certificate Authority by using SDDC Manager.
- In the navigation pane, click.
- On theWorkload Domainspage, from the table, in the domain column click the workload domain you want to view.
- On the domain summary page, click theCertificatestab.
- Generate CSR files for the target components.
- From the table, select the check box for the resource type for which you want to generate a CSR.
- ClickGenerate CSRs.
- On theDetailsdialog, configure the settings and clickNext.OptionDescriptionAlgorithmSelect the key algorithm for the certificate.Key SizeSelect the key size (2048 bit, 3072 bit, or 4096 bit) from the drop-down menu.EmailOptionally, enter a contact email address.Organizational UnitUse this field to differentiate between divisions within your organization with which this certificate is associated.Organization NameType the name under which your company is known. The listed organization must be the legal registrant of the domain name in the certificate request.LocalityType the city or locality where your company is legally registered.StateType the full name (do not abbreviate) of the state, province, region, or territory where your company is legally registered.CountryType the country name where your company is legally registered. This value must use the ISO 3166 country code.
- (Optional) On theSubject Alternative Namedialog, enter the subject alternative name(s) and clickNext.
- On theSummarydialog, clickGenerate CSRs.
- Generate signed certificates for each component.
- From the table, select the check box for the resource type for which you want to generate a signed certificate for.
- ClickGenerate Signed Certificates.
- In theGenerate Certificatesdialog box, from theSelect Certificate Authoritydrop-down menu, selectMicrosoft.
- ClickGenerate Certificates.
- Install the generated signed certificates for each component.
- From the table, select the check box for the resource type for which you want to install a signed certificate.
- ClickInstall Certificates.