<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic iLO SSL Certificate, why no SAN for short name? Or why can't we generate key and cert external in Server Management - Remote Server Management</title>
    <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7102254#M8829</link>
    <description>&lt;P&gt;I really dislike how I can add the short name of the iLO to the certificate signing request as subject alternate name, just like the IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or allow us to generate the certifcate external with key and just upload the pair.&lt;/P&gt;&lt;P&gt;If the iLO is named con-serverXXX.domain.info, the certficate ideally should really include the FQDN plus via SAN con-serverXXX, IPv4 IP and IPv6 IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Sep 2020 03:32:16 GMT</pubDate>
    <dc:creator>uzimmermann</dc:creator>
    <dc:date>2020-09-23T03:32:16Z</dc:date>
    <item>
      <title>iLO SSL Certificate, why no SAN for short name? Or why can't we generate key and cert external</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7102254#M8829</link>
      <description>&lt;P&gt;I really dislike how I can add the short name of the iLO to the certificate signing request as subject alternate name, just like the IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or allow us to generate the certifcate external with key and just upload the pair.&lt;/P&gt;&lt;P&gt;If the iLO is named con-serverXXX.domain.info, the certficate ideally should really include the FQDN plus via SAN con-serverXXX, IPv4 IP and IPv6 IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 03:32:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7102254#M8829</guid>
      <dc:creator>uzimmermann</dc:creator>
      <dc:date>2020-09-23T03:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: iLO SSL Certificate, why no SAN for short name? Or why can't we generate key and cert external</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7102544#M8831</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would suggest the best option may be to allow users to upload a PFX/PKCS12 file that includes the private key and certificate (and the ca chain?).&amp;nbsp; That way, you can use wildcards, CERTS with multiple SAN names (perhaps listing all their ILO hostnames), and short names if they so choose.&lt;/P&gt;&lt;P&gt;PFX/P12 files have passwords, so you would want to accept the file plus the password and run open SSL to split apart the key and CERT and store them in the appropriate location on the iLO.&amp;nbsp; Or allow us to upload an unencrypted RSA private key and the certificate in a webform with two fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;What you could do is to create your own&amp;nbsp;private CA in your organization and use this CA to issue the iLO certificates. &amp;nbsp;This&amp;nbsp;gives you more flexibility and control over what settings you want&amp;nbsp;enabled/disabled. &amp;nbsp;The only caveat of using a private CA is that you need to install the Certificate of this CA into your browsers and applications so, they can trust the certs issued by it.&lt;/P&gt;&lt;P&gt;Please follow the below link and make sure the server should be updated with the latest bios and ILO firmware.&lt;/P&gt;&lt;P&gt;HPE iLO 5 1.30 User Guide ( Page no 329)&lt;/P&gt;&lt;P&gt;&lt;A href="http://itdoc.hitachi.co.jp/manuals/ha8000v/hard/Gen10/iLO/880740-004_en.pdf" target="_blank"&gt;http://itdoc.hitachi.co.jp/manuals/ha8000v/hard/Gen10/iLO/880740-004_en.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;HPE iLO 4 User Guide ( Page no:74)&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.ni.com/pdf/manuals/377263a.pdf" target="_blank"&gt;http://www.ni.com/pdf/manuals/377263a.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;HPE iLO 5 Scripting and Command Line Guide ( Page No 124)&lt;/P&gt;&lt;P&gt;&lt;A href="https://server-recycling.nl/images/faq/handleidingen/HP-iLO-5-Scripting-and-Command-Line-Guide-a00018323en_us.pdf" target="_blank"&gt;https://server-recycling.nl/images/faq/handleidingen/HP-iLO-5-Scripting-and-Command-Line-Guide-a00018323en_us.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If you feel this was helpful please click the&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;KUDOS!&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;thumb below!&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 04:10:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7102544#M8831</guid>
      <dc:creator>SanjeevGoyal</dc:creator>
      <dc:date>2020-09-25T04:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: iLO SSL Certificate, why no SAN for short name? Or why can't we generate key and cert external</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7103157#M8837</link>
      <description>&lt;P&gt;Yes, we have our own private CA. Using a wild card or not certificate doesn't matter so much to me, but I wished iLO would support import of key and certificate or at least allow generation of CSR with SAN of short name in addition of IPv4 and IPv6 address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;OneView for example automatically fills the SAN with short name, FQDN and IPv4/v6 address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:57:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7103157#M8837</guid>
      <dc:creator>uzimmermann</dc:creator>
      <dc:date>2020-09-29T18:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: iLO SSL Certificate, why no SAN for short name? Or why can't we generate key and cert external</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7103180#M8838</link>
      <description>&lt;P&gt;Ok here is what I ended finally up remembering from a previous job and recreated what I had there.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use powershell to request CSR from iLO&lt;/LI&gt;&lt;LI&gt;Save CSR to disk&lt;/LI&gt;&lt;LI&gt;Grab common name from CSR and SAN&lt;/LI&gt;&lt;LI&gt;Create environment variable called ALTNAME, which lists all the SAN, i.e. "DNS:&amp;lt;FQDN&amp;gt;, DNS:&amp;lt;short&amp;gt;, IP:&amp;lt;IPv4 address&amp;gt;, IP:&amp;lt;IPv6 address"&lt;/LI&gt;&lt;LI&gt;Call the usual openssl ca operation but add "-extfile openssl-san.cnf"&lt;/LI&gt;&lt;LI&gt;Convert file to PEM and load into iLO&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The openssl-san.cnf file just contains:&lt;/P&gt;&lt;PRE&gt;basicConstraints = CA:FALSE&lt;BR /&gt;keyUsage = nonRepudiation, digitalSignature, keyEncipherment&lt;BR /&gt;subjectAltName = $ENV::ALTNAME&lt;/PRE&gt;&lt;P&gt;This will override the SAN as provided by iLO in the CSR and generates a certificate which also has the short name in it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:54:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7103180#M8838</guid>
      <dc:creator>uzimmermann</dc:creator>
      <dc:date>2020-09-30T00:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: iLO SSL Certificate, why no SAN for short name? Or why can't we generate key and cert external</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7103181#M8839</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for your update.&lt;/P&gt;&lt;P&gt;Please let us know if you have any other queries.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If you feel this was helpful please click the&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;KUDOS!&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;thumb below!&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:57:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7103181#M8839</guid>
      <dc:creator>SanjeevGoyal</dc:creator>
      <dc:date>2020-09-30T00:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: iLO SSL Certificate, why no SAN for short name? Or why can't we generate key and cert external</title>
      <link>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7118017#M8902</link>
      <description>&lt;P&gt;I am facing same issue, not having option to add additional SAN and E-Mail to the CSR request within iLO5. That is the reason company at which I work raised an Feature Request with HPE with the hope that they give us such option. Other HPE Products like OneView , OneView for Composer2, C7000 ENCs etc., all have more Field options when requesting CSR then the iLO4/5.&lt;/P&gt;&lt;P&gt;When using Microsoft CA in the Company (and nothing else allowed) the trick with openssl will not work, or with any other private CA. There is an workaround with certreq.exe when requesting Certificate, but requires the Microsoft CA option EDITF_ATTRIBUTESUBJECTALTNAME2 which is not recommended from Microsoft anymore, and on our side disabled.&lt;/P&gt;&lt;P&gt;So for us when hope that the Feature Request will be fulfilled.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 06:32:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-remote-server/ilo-ssl-certificate-why-no-san-for-short-name-or-why-can-t-we/m-p/7118017#M8902</guid>
      <dc:creator>Adis_S</dc:creator>
      <dc:date>2021-01-21T06:32:46Z</dc:date>
    </item>
  </channel>
</rss>

