<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests? in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6888254#M7819</link>
    <description>&lt;P&gt;Yes, iLO3 1.88 was released last week. &amp;nbsp;Here are the links and release notes:&lt;/P&gt;&lt;P&gt;Online ROM Flash Component for Windows x86&lt;BR /&gt;&lt;A href="ftp://ftp.hp.com/pub/softlib2/software1/sc-windows-fw-ilo/p1539977532/v116232" target="_blank"&gt;ftp://ftp.hp.com/pub/softlib2/software1/sc-windows-fw-ilo/p1539977532/v116232&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.hpe.com/global/swpublishing/MTX-3ef65d13406a41de97e6a75a3c" target="_blank"&gt;https://www.hpe.com/global/swpublishing/MTX-3ef65d13406a41de97e6a75a3c&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Online ROM Flash Component for Windows x64&lt;BR /&gt;&lt;A href="ftp://ftp.hp.com/pub/softlib2/software1/sc-windows-fw-ilo/p1015659653/v116234" target="_blank"&gt;ftp://ftp.hp.com/pub/softlib2/software1/sc-windows-fw-ilo/p1015659653/v116234&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.hpe.com/global/swpublishing/MTX-bb45e0682dd04f098ad89e189c" target="_blank"&gt;https://www.hpe.com/global/swpublishing/MTX-bb45e0682dd04f098ad89e189c&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Online ROM Flash Component for Linux&lt;BR /&gt;&lt;A href="ftp://ftp.hp.com/pub/softlib2/software1/sc-linux-fw-ilo/p1573561412/v116231" target="_blank"&gt;ftp://ftp.hp.com/pub/softlib2/software1/sc-linux-fw-ilo/p1573561412/v116231&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.hpe.com/global/swpublishing/MTX-4882dccaaa0d4fbcbd353033e6" target="_blank"&gt;https://www.hpe.com/global/swpublishing/MTX-4882dccaaa0d4fbcbd353033e6&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Online ROM Flash Component for VMware ESXi&lt;BR /&gt;&lt;A href="ftp://ftp.hp.com/pub/softlib2/software1/sc-linux-fw-ilo/p986822869/v116230" target="_blank"&gt;ftp://ftp.hp.com/pub/softlib2/software1/sc-linux-fw-ilo/p986822869/v116230&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.hpe.com/global/swpublishing/MTX-04b05621285145119cbaa69982" target="_blank"&gt;https://www.hpe.com/global/swpublishing/MTX-04b05621285145119cbaa69982&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enhancements:&lt;BR /&gt;iLO 3 v1.88 includes the following enhancements:&lt;BR /&gt;- Added support for AES-CTR ciphers and HMAC-SHA2-256 to the SSH server.&lt;BR /&gt;- Disabled the CBC ciphers in the SSH server when iLO 3 is in FIPS mode or when the Enforce AES/3DES Encryption option is enabled.&lt;BR /&gt;- Certificate Signing Requests now use the SHA256 algorithm for the signature.&lt;BR /&gt;- The Java IRC now includes two alternatives: A Java Web Start console and a Java applet-based console. The Java Web Start option works in newer browsers that do not allow the applet version to run. On systems with OpenJDK, you must use the Java applet-based console with a browser (such as Firefox) that supports a Java plug-in.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Fixes:&lt;BR /&gt;The following issues are resolved in this version:&lt;BR /&gt;- Addressed Security Bulletins HPSBHF03440 and HPSBHF03441.&lt;BR /&gt;- Removed the iLO 3 short-name from the SAN field in the Certificate Signing Request.&lt;BR /&gt;- Changed the IPMI master write read completion code to avoid retries by the open IPMI driver.&lt;BR /&gt;- Changed the IPMI close session request to utilize the session handle, if present.&lt;BR /&gt;- Fixed the IPMI channel privilege level setting.&lt;BR /&gt;- Fixed an issue that allowed authenticated iLO web interface users to use browser debug tools to set their own password below the configured minimum password length.&lt;BR /&gt;- Fixed an issue that prevents users from using the CLI to set a password that contains the "\" character.&lt;BR /&gt;- Disabled TLSv1.0 when the FIPS mode or Enforce AES/3DES Encryption options are enabled.&lt;BR /&gt;- Added X-Frame-Options to the HTTP header as a countermeasure for Clickjacking.&lt;BR /&gt;- Fixed an issue in which the IPMI Set SOL Configuration parameters return an error completion code when the configuration change was successful&lt;BR /&gt;- Fixed IPMI OEM commands for setting and getting the serial number and product ID.&lt;BR /&gt;- Fixed an intermittent loss of OA communications after an iLO firmware update on a blade server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2016 14:42:55 GMT</pubDate>
    <dc:creator>Oscar A. Perez</dc:creator>
    <dc:date>2016-08-12T14:42:55Z</dc:date>
    <item>
      <title>Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6840442#M7729</link>
      <description>&lt;P&gt;My signing authority is no accept the SSL for only the iLo 4.&lt;/P&gt;&lt;P&gt;The old iLo 2 worked fine.&lt;/P&gt;&lt;P&gt;For whatever reason the iLo 4 certs have Subject Alternative Names as "shortname, fqdn.domain.com"&lt;/P&gt;&lt;P&gt;The iLo 2 just had the full quailfied domain names.&lt;BR /&gt;Is there any place where I can remove the short name in the ssl cert CSR?&lt;/P&gt;&lt;P&gt;I couldn't seem to find anywhere in the iLo 4 configs,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 03:43:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6840442#M7729</guid>
      <dc:creator>david8881</dc:creator>
      <dc:date>2016-03-10T03:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6843446#M7735</link>
      <description>&lt;P&gt;iLo3 has the same problem.&amp;nbsp; Which means we cannot use a certificate from an external CA (such as letsencrpyt).&lt;/P&gt;</description>
      <pubDate>Sun, 20 Mar 2016 23:19:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6843446#M7735</guid>
      <dc:creator>briank2012</dc:creator>
      <dc:date>2016-03-20T23:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6843457#M7736</link>
      <description>&lt;P&gt;I realize some people want the shortname in the SAN so they can just type it into their browser (they must have local host file entries?).&amp;nbsp; I think the best option may be to allow use to upload a PFX/PKCS12 file that includes the private key and certificate (and the ca chain?).&amp;nbsp; That way, people can use wildcards, certs with multiple SAN names (perhaps listing all their ILO hostnames), and shortnames if they so choose.&lt;/P&gt;&lt;P&gt;PFX/P12 files have passwords, so you would want to accept the file plus the password and run openssl to split apart the key and cert and store them in the appropriate location on the iLO.&amp;nbsp; Or allow us to upload an unencrypted RSA private key and the certificate in a webform with two fields.&lt;/P&gt;&lt;P&gt;Whatever you do, can you please also fix iLo3 as well?&amp;nbsp; Please!&lt;/P&gt;&lt;P&gt;-Brian&lt;/P&gt;</description>
      <pubDate>Sun, 20 Mar 2016 23:59:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6843457#M7736</guid>
      <dc:creator>briank2012</dc:creator>
      <dc:date>2016-03-20T23:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6845098#M7739</link>
      <description>&lt;P&gt;What version of iLO4 do you have? &amp;nbsp;Versions 2.10 and later do not add the short name in the SAN. &amp;nbsp;Only FQDN is added which should be okay with all CAs.&lt;/P&gt;&lt;P&gt;As for the iLO3, we are&amp;nbsp;working on a new version that will remove the short name from the SAN as well. &amp;nbsp;&lt;/P&gt;&lt;P&gt;All these said, I would not use Public CAs to sign iLO certificates. &amp;nbsp;It doesn't make sense&amp;nbsp;unless or course, you are planning to expose your iLOs directly to the Internet, which is NOT recommended at all.&lt;/P&gt;&lt;P&gt;What you could do is to create your own&amp;nbsp;private CA in your organization and use this CA to issue the iLO certificates. &amp;nbsp;This&amp;nbsp;gives you more flexibility and control over what settings you want&amp;nbsp;enabled/disabled. &amp;nbsp;The only caveat of using a private CA is that you need to install the Certificate of this CA into your browsers and applications so, they can trust the certs issued by it.&lt;/P&gt;&lt;P&gt;About importing PCKS#12 Certificates with both Private/Public keys into iLO. &amp;nbsp;We don't currently support it due to security reasons. &amp;nbsp;First, the Private/Public key-pairs need to be stored somewhere and they could be compromised. &amp;nbsp;As opposed to iLO generating its own&amp;nbsp;key material and keeping its&amp;nbsp;Private Key secret and secure. &amp;nbsp; Second, we would have no&amp;nbsp;control over the quality of the Pseudo Random Number Generator used by&amp;nbsp;the tool generating the key material, how it is seeded and how much entropy it would&amp;nbsp;contain. &amp;nbsp;And&amp;nbsp;third, it allows users&amp;nbsp;to do stupid things like importing the same Private/Public RSA key-pair&amp;nbsp;into hundreds of iLOs which could make it easier for adversaries to factorize one&amp;nbsp;RSA key by attacking all of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that setting a CA and getting trusted certificates imported into each iLO is a royal pain but, security isn't something that comes inside a retail box that you can buy from a store. &amp;nbsp;It requires work.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 19:50:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6845098#M7739</guid>
      <dc:creator>Oscar A. Perez</dc:creator>
      <dc:date>2016-04-04T19:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6847703#M7741</link>
      <description>&lt;P&gt;Yes, for the iLo4s the latest firmware fixed the issue.&lt;/P&gt;&lt;P&gt;For the iLo3 the new firmware will not be out till "summer" HP support tells me.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 19:18:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6847703#M7741</guid>
      <dc:creator>david8881</dc:creator>
      <dc:date>2016-04-04T19:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6847706#M7742</link>
      <description>&lt;P&gt;I believe for ilo3 we should be able to generate the cert with just openssl and import it with locfg.pl or hpqlocfg.exe.&lt;/P&gt;&lt;P&gt;I am still trying to figure this out.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 19:21:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6847706#M7742</guid>
      <dc:creator>david8881</dc:creator>
      <dc:date>2016-04-04T19:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6888004#M7818</link>
      <description>&lt;P&gt;Any updated news on when the new version for ILO3 will be out?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2016 21:01:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6888004#M7818</guid>
      <dc:creator>tstrothe</dc:creator>
      <dc:date>2016-08-11T21:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6888254#M7819</link>
      <description>&lt;P&gt;Yes, iLO3 1.88 was released last week. &amp;nbsp;Here are the links and release notes:&lt;/P&gt;&lt;P&gt;Online ROM Flash Component for Windows x86&lt;BR /&gt;&lt;A href="ftp://ftp.hp.com/pub/softlib2/software1/sc-windows-fw-ilo/p1539977532/v116232" target="_blank"&gt;ftp://ftp.hp.com/pub/softlib2/software1/sc-windows-fw-ilo/p1539977532/v116232&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.hpe.com/global/swpublishing/MTX-3ef65d13406a41de97e6a75a3c" target="_blank"&gt;https://www.hpe.com/global/swpublishing/MTX-3ef65d13406a41de97e6a75a3c&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Online ROM Flash Component for Windows x64&lt;BR /&gt;&lt;A href="ftp://ftp.hp.com/pub/softlib2/software1/sc-windows-fw-ilo/p1015659653/v116234" target="_blank"&gt;ftp://ftp.hp.com/pub/softlib2/software1/sc-windows-fw-ilo/p1015659653/v116234&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.hpe.com/global/swpublishing/MTX-bb45e0682dd04f098ad89e189c" target="_blank"&gt;https://www.hpe.com/global/swpublishing/MTX-bb45e0682dd04f098ad89e189c&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Online ROM Flash Component for Linux&lt;BR /&gt;&lt;A href="ftp://ftp.hp.com/pub/softlib2/software1/sc-linux-fw-ilo/p1573561412/v116231" target="_blank"&gt;ftp://ftp.hp.com/pub/softlib2/software1/sc-linux-fw-ilo/p1573561412/v116231&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.hpe.com/global/swpublishing/MTX-4882dccaaa0d4fbcbd353033e6" target="_blank"&gt;https://www.hpe.com/global/swpublishing/MTX-4882dccaaa0d4fbcbd353033e6&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Online ROM Flash Component for VMware ESXi&lt;BR /&gt;&lt;A href="ftp://ftp.hp.com/pub/softlib2/software1/sc-linux-fw-ilo/p986822869/v116230" target="_blank"&gt;ftp://ftp.hp.com/pub/softlib2/software1/sc-linux-fw-ilo/p986822869/v116230&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.hpe.com/global/swpublishing/MTX-04b05621285145119cbaa69982" target="_blank"&gt;https://www.hpe.com/global/swpublishing/MTX-04b05621285145119cbaa69982&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enhancements:&lt;BR /&gt;iLO 3 v1.88 includes the following enhancements:&lt;BR /&gt;- Added support for AES-CTR ciphers and HMAC-SHA2-256 to the SSH server.&lt;BR /&gt;- Disabled the CBC ciphers in the SSH server when iLO 3 is in FIPS mode or when the Enforce AES/3DES Encryption option is enabled.&lt;BR /&gt;- Certificate Signing Requests now use the SHA256 algorithm for the signature.&lt;BR /&gt;- The Java IRC now includes two alternatives: A Java Web Start console and a Java applet-based console. The Java Web Start option works in newer browsers that do not allow the applet version to run. On systems with OpenJDK, you must use the Java applet-based console with a browser (such as Firefox) that supports a Java plug-in.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Fixes:&lt;BR /&gt;The following issues are resolved in this version:&lt;BR /&gt;- Addressed Security Bulletins HPSBHF03440 and HPSBHF03441.&lt;BR /&gt;- Removed the iLO 3 short-name from the SAN field in the Certificate Signing Request.&lt;BR /&gt;- Changed the IPMI master write read completion code to avoid retries by the open IPMI driver.&lt;BR /&gt;- Changed the IPMI close session request to utilize the session handle, if present.&lt;BR /&gt;- Fixed the IPMI channel privilege level setting.&lt;BR /&gt;- Fixed an issue that allowed authenticated iLO web interface users to use browser debug tools to set their own password below the configured minimum password length.&lt;BR /&gt;- Fixed an issue that prevents users from using the CLI to set a password that contains the "\" character.&lt;BR /&gt;- Disabled TLSv1.0 when the FIPS mode or Enforce AES/3DES Encryption options are enabled.&lt;BR /&gt;- Added X-Frame-Options to the HTTP header as a countermeasure for Clickjacking.&lt;BR /&gt;- Fixed an issue in which the IPMI Set SOL Configuration parameters return an error completion code when the configuration change was successful&lt;BR /&gt;- Fixed IPMI OEM commands for setting and getting the serial number and product ID.&lt;BR /&gt;- Fixed an intermittent loss of OA communications after an iLO firmware update on a blade server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2016 14:42:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6888254#M7819</guid>
      <dc:creator>Oscar A. Perez</dc:creator>
      <dc:date>2016-08-12T14:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6951386#M7889</link>
      <description>&lt;P&gt;I'm using iLO4. How do I get rid of the IP fields in the SAN section (and why is this there at all)? The IP SANs prohibt us from using an official certificate.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Mar 2017 09:40:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6951386#M7889</guid>
      <dc:creator>spellbreaker</dc:creator>
      <dc:date>2017-03-26T09:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6951575#M7891</link>
      <description>&lt;P&gt;But then you have to install your CA-Cert into every device you whish to use with your iLO-servers.. For an android device this means that you have to live with a system generated warning.... Actually I think it is a good idea to use an official CA even when you only connect from inside of your company. Imho using a private CA is only useful for authentification.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 12:44:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6951575#M7891</guid>
      <dc:creator>spellbreaker</dc:creator>
      <dc:date>2017-03-27T12:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6952270#M7892</link>
      <description>&lt;P&gt;Within&amp;nbsp;the next few weeks, we'll release a new iLO4 firmware that will let users&amp;nbsp;choose if they&amp;nbsp;want to include the iLO IP address(es) in the SAN.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 15:26:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/6952270#M7892</guid>
      <dc:creator>Oscar A. Perez</dc:creator>
      <dc:date>2017-03-29T15:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Anyway to change the Subject Alternative Name on iLo SSL Cert Requests?</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/7183267#M9653</link>
      <description>&lt;P&gt;This still doesn't explain how to add the shortname to the SAN list when generating a cert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been playing around with the iLO Powershell cmdlets and as far as I can see the cmdlet only supports the "CN" field using an FQDN.&lt;/P&gt;&lt;P&gt;Is it possible to pass a parameter for the "subjectaltname" field typically used by OpenSSL conf files?&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the field capabilities don not include the ability to specify the subjectaltname, however, iLO must do this when adding the IP option to the SAN list.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to add the shortname "server-ilo" to the SAN list, along with the FQDN and the IP.&lt;/P&gt;&lt;P&gt;e.g. here's the edited/redacted output of a:&lt;/P&gt;&lt;P&gt;Get-HPEiLOCertificateSigningRequest -Connection $connection -OutputType RawRequest&lt;/P&gt;&lt;P&gt;The Start-HPEiLOCertificateSigningRequest cmdlet doesn't appear to support anything more than the CN field, no subjectaltname option.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Target: &lt;FONT color="#0000FF"&gt;server-ilo.domain.local&lt;/FONT&gt;&lt;BR /&gt;URL: https://&lt;FONT color="#0000FF"&gt;server-ilo.domain.local&lt;/FONT&gt;/rest/v1/Managers/1/SecurityService/HttpsCert&lt;BR /&gt;ContentType: application/json&lt;BR /&gt;Response: {"@odata.context":"/redfish/v1/$metadata#Managers/Members/1/SecurityService/HttpsCert$entity","@odata.id":"/redfish/v1/Managers/1/SecurityService/HttpsCert/","@odata.type":"#HpHttpsCert.1.0.0.HpHttpsCert","Actions":{"#HpHttpsCert.GenerateCSR":{"target":"/redfish/v1/Managers/1/SecurityService/HttpsCert/Actions/HpHttpsCert.GenerateCSR/"},"#HpHttpsCert.ImportCertificate":{"target":"/redfish/v1/Managers/1/SecurityService/HttpsCert/Actions/HpHttpsCert.ImportCertificate/"}},"AvailableActions":[{"Action":"GenerateCSR","Capabilities":[&lt;FONT color="#00FF00"&gt;&lt;FONT color="#0000FF"&gt;{"PropertyName":"City"},{"PropertyName":"CommonName"},{"PropertyName":"Country"},{"PropertyName":"IncludeIP"},{"PropertyName":"OrgName"},{"PropertyName":"OrgUnit"},{"PropertyName":"State"}]},{"Action":"ImportCertificate","Capabilities":[{"PropertyName":"Certificate"}]}]&lt;/FONT&gt;,&lt;/FONT&gt;"CertificateSigningRequest":null,"Id":"HttpsCert","Type":"HpHttpsCert.1.0.0","X509CertificateInformation":{"Issuer":"C = GB, O = XXXXX, OU = XXXXXX, CN = XXXXXX","SerialNumber":"XXXXX","Subject":"C = XX, ST = XX, L = XX, O = XX, OU = XX, &lt;FONT color="#0000FF"&gt;CN = server-ilo.domain.local&lt;/FONT&gt;","ValidNotAfter":"2026-01-23T10:05:05Z","ValidNotBefore":"2023-01-24T10:05:05Z"},"links":{"self":{"href":"/rest/v1/Managers/1/SecurityService/HttpsCert"}}}&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 18:30:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/anyway-to-change-the-subject-alternative-name-on-ilo-ssl-cert/m-p/7183267#M9653</guid>
      <dc:creator>SysAdman</dc:creator>
      <dc:date>2023-02-22T18:30:28Z</dc:date>
    </item>
  </channel>
</rss>

