LINUXOR.SK ... open source notes ...

NetApp - ONTAP CA-signed certificate for the cluster and self-signed certificates for the SVMs

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

NetApp Solution · Config document · referenced from Encryption and certificates

notegenerate-csr prints the private key on the terminal and does not keep it. Whatever is used to carry it to the install step holds a private key in clear text and must be cleaned afterwards. All certificate text, keys and serial numbers are placeholders here.

The commands that replace the self-signed certificate of a cluster's management web service with one signed by the internal CA, and that give each data SVM a new self-signed certificate.

ItemValue
Runs oncluster shell, as admin
Shown hereDC1-A-XNAS001 and its SVM DC1-S-VCVSM001
Also applied toDC1-B-XNAS001; SVMs 002, 003 and 006 on cluster A and 004 on cluster B; site 2 clusters by the design, without notes
Key size2048 bit RSA
ValidityCA-signed: one year. Self-signed SVM certificates: 3652 days
ONTAP version at the time9.1P8 for the first certificates

The command set

bash
# --- Cluster (admin SVM): certificate signed by the internal CA --------------

# 1. Generate key and signing request. Both are printed; copy both.
security certificate generate-csr -common-name dc1-a-xnas001.adm.example.net -size 2048 -country <COUNTRY_CODE> -locality <LOCALITY> -organization "Example Org" -email-addr admin01@example.net

# 2. Have the request signed by the internal CA (outside ONTAP)

# 3. Install the signed certificate with its key. The command prompts:
#      Please enter Certificate:  <PASTE SIGNED CERTIFICATE>
#      Please enter Private Key:  <PASTE PRIVATE KEY FROM STEP 1>
#      Do you want to continue entering root and/or intermediate
#      certificates {y|n}: n
security certificate install -vserver DC1-A-XNAS001 -type server

# 4. List the certificates and read the serial number of the new one
#    (Certificate Authority: Internal CA)
security certificate show

# 5. Point the web service of the cluster at the new certificate
security ssl modify -vserver DC1-A-XNAS001 -ca "Internal CA" -serial <CERT_SERIAL> -common-name dc1-a-xnas001.adm.example.net -server-enabled true -client-enabled false

# 6. Verify
security ssl show

# --- Data SVM: new self-signed certificate, valid ten years -------------------

# 7. Create the certificate
certificate create -common-name DC1-S-VCVSM001 -type server -size 2048 -country <COUNTRY_CODE> -locality <LOCALITY> -organization "Example Org" -email-addr admin01@example.net -expire-days 3652 -vserver DC1-S-VCVSM001

# 8. Delete the old certificate of the SVM
certificate delete -serial <OLD_CERT_SERIAL> *

# 9. Point the web service of the SVM at the new certificate and verify
security ssl modify -server-enabled true -vserver DC1-S-VCVSM001 -common-name DC1-S-VCVSM001 -serial <CERT_SERIAL> -ca DC1-S-VCVSM001
security ssl show -vserver DC1-S-VCVSM001 -instance

Differences between the runs:

RunCommon nameE-mail in the subject
DC1-A-XNAS001dc1-a-xnas001.adm.example.netadmin01@example.net
DC1-B-XNAS001dc1-b-xnas001.adm.example.netadmin01@example.net
SVMs 001, 003, 004name of the SVMadmin01@example.net
SVMs 002, 006, on 8 July 2019name of the SVMinfra.security@example.net

For the cluster certificates issued in 2019 the design lists a shared mailbox in the subject (security@example.net, for the site 2 clusters infra.security@example.net) and an organisational unit, which the commands of 2017 do not have. The first requests carried a personal address, which is one more thing that outlives the person.

The notes do not show the old cluster certificate being deleted after step 5, nor the CA certificate being installed as a chain; the prompt in step 3 was answered with n.

Checked against ONTAP 9.19.1

As builtToday
security certificate generate-csr … -size 2048Valid. -size is deprecated since ONTAP 9.8 in favour of -security-strength. New options: -algorithm (RSA or EC), -hash-function (default SHA256) and subject alternative names (-dns-name, -ipaddr, -uri, -rfc822-name)
Request without subject alternative nameThe as-built requests carried none; a request can now carry them
security certificate install -vserver … -type serverValid; adds -cert-name
security certificate create … -expire-days 3652Valid. -expire-days takes 1 to 3652, the default is 365
security ssl modify -ca … -serial … -common-name …Valid; adds OCSP options

The procedure is unchanged in its steps. A request made today should carry the DNS name as a subject alternative name. Ten years remains the maximum for a self-signed certificate, not a recommendation.

← solutionz