| Unique Visitors |
Hi Jonathan, To answer your questions, 1. CN change is fine. So you can have the same OU on multiple servers because the CN is different and therefore the DN is then unique. 2. Doesn't apply unless you're trying to apply certs to SRM. That advice is only for SRM. 3. There are example CSR's that include the OU attribute. You can choose to just copy those or choose your own. 4. The name needs to be rui. If you want to automate the process check out the article I wrote about vCert Manager, which is being developed by one of VMware's partners. Also check out VMware's cert tool.
]]>1. They indicate that the DN must be unique via OU matching the component function. They do not however list what to do if you have multiple servers running the same function (i.e. multiple vCenters). In this case, would the different CN be enough or do the OU need to not only be the function but vCenter environment.
2. They do not have a warning that the real hostname FQDN must be last in the SAN list. http://virtuallyhyper.com/2012/08/srm-5-x-custom-…
3. In KB 2015499, they reference 2037432 but to not provide a suggestion on what a proper OU would be. This is also related to the first question.
4. Is the name rui.csr/key/cer required or just conventional? When dealing with a large number of certs, it makes more sense to prefix the host shortname just to be certain you don't get your rui* mixed up accidentally.
]]>We have considered it, but because we pay a lot for Enterprise edition licenses, VMware should provide proper documentation or make it simpler to upgrade to 5.1 and also prepare their technical staff to be able to support the more complex installs, such as the SSO servers in HA config with SSL certs. Many in the VMware community think VMware has really dropped the ball on this one.
]]>Hi Hugh, Not sure about the guys in Support, but I'd suggest VMware PSO has likely done this and potentially some of the VMware Partners. I haven't tried the update to 5.1.0b in that scenario myself yet. Have you considered a brief T&M engagement with VMware PSO?
]]>I've engaged VMware technical support and not one person on their floor of technicians has done an upgrade to 5.1 using SSO in HA configuration with a load balancer and SSL certificates. VMware's documentation isn't great for the SSL part when using a load balancer with SSO in HA mode….. Its ok if you do the single vCenter, SSO, Inv all in one install for small environments…but not if you want redundancy.
I'd be interested if anyone in VMware support has successfully got this working?
]]>Yup, been pretty busy but will be tweaking the articles a little bit more. Thanks for the shout out!
]]>