<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OneView CERT in HPE OneView</title>
    <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7002463#M3089</link>
    <description>&lt;P&gt;You need both Server AND Client authentication. Do you have both?&lt;/P&gt;</description>
    <pubDate>Fri, 13 Apr 2018 14:32:11 GMT</pubDate>
    <dc:creator>John Bigg</dc:creator>
    <dc:date>2018-04-13T14:32:11Z</dc:date>
    <item>
      <title>OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/6999865#M3084</link>
      <description>&lt;P&gt;I am trying to import a cert from my windows CA DC to my new 4.0 OneView appliance.&lt;/P&gt;&lt;P&gt;I am first generating the CR from the OneView appliance. Then I create it from my Windows CA using teh WebServer2048 option.&lt;/P&gt;&lt;P&gt;I keep getting the below error message: The certificate is not valid&lt;/P&gt;&lt;P&gt;Unable to import signed certificate.&lt;BR /&gt;Extended Key Usage(EKU) field in the certificate does not contain Server Authentication and/or Client Authentication&lt;/P&gt;&lt;P&gt;Resolution Provide a valid certificate with EKU field set as specified&lt;/P&gt;&lt;P&gt;If the issue persists, Create a support dump and contact your authorized support representative for assistance.&lt;/P&gt;&lt;P&gt;Please advise...&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 20:58:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/6999865#M3084</guid>
      <dc:creator>Scott Caryer</dc:creator>
      <dc:date>2018-03-15T20:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/6999876#M3085</link>
      <description>&lt;P&gt;The message is quite clear what is wrong.&amp;nbsp; The SSL certificate you created must contain the &lt;STRONG&gt;Server Authentication&lt;/STRONG&gt; attribute set.&amp;nbsp; Take a look at the screenshot of a certificate deployed on my appliance.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Cert Enhanced Key Usage.png" style="width: 318px;"&gt;&lt;img src="https://community.hpe.com/t5/image/serverpage/image-id/102053iB59DDC32EE8017B4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Cert Enhanced Key Usage.png" alt="Cert Enhanced Key Usage.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm also attaching the Web Server Certificate Template policy I used on my Windows Server 2016 CA&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Web Server CA Template.png" style="width: 305px;"&gt;&lt;img src="https://community.hpe.com/t5/image/serverpage/image-id/102054iCFA2F9F4F651A7CE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Web Server CA Template.png" alt="Web Server CA Template.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 22:15:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/6999876#M3085</guid>
      <dc:creator>ChrisLynch</dc:creator>
      <dc:date>2018-03-15T22:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/6999878#M3086</link>
      <description>&lt;P&gt;Thanks for your reply Chris! I see the buck stops with you here in the OneView forums.&lt;/P&gt;&lt;P&gt;So I generated the&amp;nbsp;certificate request through the&amp;nbsp;"Guided Section" area on&amp;nbsp;my &amp;nbsp;OneView appliance(&lt;SPAN&gt;4.00.07-0330056&lt;/SPAN&gt;). I then generated the cert from my Windows 2012 CA utility seen in the attachment. I selected the "WedServer2048" for the Certificate Template. I do not have a certificate template for Server authenication. So I am a little confused on how to create the certificate properly. The install guide does not talk much about installing a cert on the appliance.&lt;/P&gt;&lt;P&gt;Thanks for any assistance. As you can tell, cert management is not my speciality.&lt;/P&gt;&lt;P&gt;Any additional info woudl be great.&lt;/P&gt;&lt;P&gt;Thanks in advance, Scott&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 02:11:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/6999878#M3086</guid>
      <dc:creator>Scott Caryer</dc:creator>
      <dc:date>2018-03-16T02:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/6999880#M3087</link>
      <description>&lt;P&gt;The reason why we don't document the CA part is that every customer is different, and uses different enterprise CA products.&amp;nbsp; Since you are using Microsoft Enterprise Certificate Authority Services, it's quite simple.&amp;nbsp; On your Issuing CA, you need to make sure a Web Server Template is available, or a CA Template Policy that is configured with the Enhanced Key Usage policy I showed in the screenshot.&amp;nbsp; Also, review these Microsoft Technet links (&lt;A href="https://blogs.technet.microsoft.com/askds/2010/05/27/designing-and-implementing-a-pki-part-iii-certificate-templates/" target="_blank"&gt;Link1 &lt;/A&gt;and &lt;A href="https://blogs.technet.microsoft.com/askds/2011/04/06/designing-and-implementing-a-pki-part-iv-configuring-ssl-for-web-enrollment-and-enabling-key-archival/" target="_blank"&gt;Link2&lt;/A&gt;) on how to configure a Certificate Template Policy.&amp;nbsp; Even though those links are for Windows Server 2003, they still apply to Server 2008, Server 2012 and Server 2016.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 02:22:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/6999880#M3087</guid>
      <dc:creator>ChrisLynch</dc:creator>
      <dc:date>2018-03-16T02:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7002413#M3088</link>
      <description>&lt;P&gt;I too have had this error, however my WebServer template does allow for EKU and the certificate does show Server Authentication as a valid purpose (same as in your certificate as shown).&lt;/P&gt;&lt;P&gt;We too are using MS CA.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Apr 2018 06:34:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7002413#M3088</guid>
      <dc:creator>Romper</dc:creator>
      <dc:date>2018-04-13T06:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7002463#M3089</link>
      <description>&lt;P&gt;You need both Server AND Client authentication. Do you have both?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Apr 2018 14:32:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7002463#M3089</guid>
      <dc:creator>John Bigg</dc:creator>
      <dc:date>2018-04-13T14:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7007068#M3090</link>
      <description>&lt;P&gt;I have the same issue&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 07:14:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7007068#M3090</guid>
      <dc:creator>bronman</dc:creator>
      <dc:date>2018-05-25T07:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7007303#M3091</link>
      <description>&lt;P&gt;You need to make sure that your CA honours the request for the EKU fields Server Authentication and Client Authentication. One or both of these are missing from the certificate generated by your CA.&lt;/P&gt;</description>
      <pubDate>Tue, 29 May 2018 12:34:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7007303#M3091</guid>
      <dc:creator>John Bigg</dc:creator>
      <dc:date>2018-05-29T12:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7007657#M3092</link>
      <description>&lt;P&gt;Hello Scott,&lt;/P&gt;&lt;P&gt;that's what I've got (after some lengthy discussion) from HPE support:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;If you create a Certificate Signing Request (CSR) in OV, it will request the following usages:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; X509v3 Key Usage:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Digital Signature, NonRepudiation, Key Encipherment&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; X509v3 Extended Key Usage:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS Web ServerAuthentication, TLS Web Client Authentication&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;If you submit this CSR to your CA, the resulting certificate should contain all these features.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Make sure, that your CA will generate a ceritifcate that includes ALL of above.&lt;/P&gt;&lt;P&gt;Had to get our CA team to try several times, until OneView was satisfied with the generated certificate.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 11:34:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7007657#M3092</guid>
      <dc:creator>Daniel-L</dc:creator>
      <dc:date>2018-06-01T11:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7007896#M3093</link>
      <description>&lt;P&gt;Duplicate WebServer template, check ServerAuth and add ClientAuth, add&amp;nbsp;Non Repudiation... add Template in your CA and&amp;nbsp;Works!&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 20:27:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7007896#M3093</guid>
      <dc:creator>Denialmix</dc:creator>
      <dc:date>2018-06-04T20:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7119670#M6016</link>
      <description>&lt;P&gt;Here's the steps for someone using a Microsoft cert authority in their windows domain.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&amp;nbsp;Create the cert request from Oneview&lt;OL&gt;&lt;LI&gt;Log into Oneview and from the NAV in the top left select Settings.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Click on Security&lt;/LI&gt;&lt;LI&gt;In the Actions menu top right, select Create appliance certificate signing request&lt;/LI&gt;&lt;LI&gt;Fill in the details and click OK to get the large text block containing the base64 encoded cert request.&lt;/LI&gt;&lt;LI&gt;Copy the cert request to your clipboard or save the text in Notepad.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Create a certificate template that OneView will be happy with.&lt;OL&gt;&lt;LI&gt;&amp;nbsp;On your Windows CA, open the "Certification Authority" app.&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;In the tree on the left side, right-click on Certificate Template and select Manage.&lt;/LI&gt;&lt;LI&gt;Scroll down to Web Server and right-click select Duplicate Template&lt;/LI&gt;&lt;LI&gt;On the General tab, tweak the names to your liking. I use "HPE OneView".&lt;/LI&gt;&lt;LI&gt;On the Extensions tab, click Application Policies and click Edit. Add Client Authentication. Click OK. You should now have both Server Authentication and Client Authentication.&lt;/LI&gt;&lt;LI&gt;On the same Extensions tab, click Key Usage and click Edit. Checkmark "signature is proof of origin (nonrepudiation)". Ensure Allow key exchange only with key encryption (key encipherment) radio button is selected. Click OK.&lt;/LI&gt;&lt;LI&gt;On the Security tab, apply read and enroll to whichever user account will be requesting the cert from this CA (ie: domain admins, your windows account, etc).&amp;nbsp; I use my domain admin account.&lt;/LI&gt;&lt;LI&gt;Click OK/Apply and close editing that template.&lt;/LI&gt;&lt;LI&gt;Back at the main Certification Authority screen, right click again on the Certificate Template folder and select New -&amp;gt; Certificate Template to issue.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Choose the certificate template you just duplicated (in my case: HPE OneView).&lt;/LI&gt;&lt;LI&gt;Verify that you see it in the list.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Request the certificate from your CA using the new template&lt;OL&gt;&lt;LI&gt;Open a web browser and navigate to your CA's webpage.&amp;nbsp; In my case:&amp;nbsp;http://dc09/certsrv&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Click on "Download a CA Certificate, certificate Chain, or CRL&lt;/LI&gt;&lt;LI&gt;Select Base64 and click Download CA Certificate - Name it CA-cert.txt and save it somewhere.&lt;/LI&gt;&lt;LI&gt;Go back to the home page and click Request a Certificate&lt;/LI&gt;&lt;LI&gt;Click Advanced Certificate Request&lt;/LI&gt;&lt;LI&gt;Click Create and Submit a request to this CA.&lt;/LI&gt;&lt;LI&gt;Paste in the base64 text copied from step 1 and in Certificate Template select the template name you just created, in my case HPE OneView.&lt;/LI&gt;&lt;LI&gt;Click Submit.&lt;/LI&gt;&lt;LI&gt;Select Base64 encoded and click Download Certificate, save the file oneview.txt.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Import both the CA and the server certificate into Oneview.&lt;OL&gt;&lt;LI&gt;Back on the Security settings page of OneView, click on Actions &amp;gt; Manage Certificates&lt;/LI&gt;&lt;LI&gt;Click Add Certificate&lt;/LI&gt;&lt;LI&gt;Using Notepad, open the CA-cert.txt file you downloaded in step 3-3 above. Copy and paste the base64 text into the dialog and then click Add.&lt;/LI&gt;&lt;LI&gt;Assuming no issues, close that page and then click Actions &amp;gt; Import Appliance certificate.&lt;/LI&gt;&lt;LI&gt;Open the oneview.txt cert downloaded in step 3-9 above and copy/paste the text into this Import cert dialog.&lt;/LI&gt;&lt;LI&gt;Click OK and if all goes well, no errors and the system will import the cert.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Next time you browse the page you should get a happy cert.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 16:50:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7119670#M6016</guid>
      <dc:creator>CorbettEnders</dc:creator>
      <dc:date>2021-02-03T16:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: OneView CERT</title>
      <link>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7208331#M9051</link>
      <description>&lt;P&gt;Followed&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1131532"&gt;@CorbettEnders&lt;/a&gt;&amp;nbsp; detailed directions, worked perfectly for us!&lt;/P&gt;&lt;P&gt;Only addition was giving the user that was doing the certificate intall enrollment rights on the certificate template.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 18:48:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/oneview-cert/m-p/7208331#M9051</guid>
      <dc:creator>kpatelvno</dc:creator>
      <dc:date>2024-03-07T18:48:58Z</dc:date>
    </item>
  </channel>
</rss>

