NetApp - ONTAP CA-signed certificate for the cluster and self-signed certificates for the SVMs
NetApp Solution · Config document · referenced from Encryption and certificates
generate-csr prints the private key on the terminal and does not keep it. Whatever is used to carry it to the install step holds a private key in clear text and must be cleaned afterwards. All certificate text, keys and serial numbers are placeholders here.The commands that replace the self-signed certificate of a cluster's management web service with one signed by the internal CA, and that give each data SVM a new self-signed certificate.
| Item | Value |
|---|---|
| Runs on | cluster shell, as admin |
| Shown here | DC1-A-XNAS001 and its SVM DC1-S-VCVSM001 |
| Also applied to | DC1-B-XNAS001; SVMs 002, 003 and 006 on cluster A and 004 on cluster B; site 2 clusters by the design, without notes |
| Key size | 2048 bit RSA |
| Validity | CA-signed: one year. Self-signed SVM certificates: 3652 days |
| ONTAP version at the time | 9.1P8 for the first certificates |
The command set
# --- Cluster (admin SVM): certificate signed by the internal CA -------------- # 1. Generate key and signing request. Both are printed; copy both. security certificate generate-csr -common-name dc1-a-xnas001.adm.example.net -size 2048 -country <COUNTRY_CODE> -locality <LOCALITY> -organization "Example Org" -email-addr admin01@example.net # 2. Have the request signed by the internal CA (outside ONTAP) # 3. Install the signed certificate with its key. The command prompts: # Please enter Certificate: <PASTE SIGNED CERTIFICATE> # Please enter Private Key: <PASTE PRIVATE KEY FROM STEP 1> # Do you want to continue entering root and/or intermediate # certificates {y|n}: n security certificate install -vserver DC1-A-XNAS001 -type server # 4. List the certificates and read the serial number of the new one # (Certificate Authority: Internal CA) security certificate show # 5. Point the web service of the cluster at the new certificate security ssl modify -vserver DC1-A-XNAS001 -ca "Internal CA" -serial <CERT_SERIAL> -common-name dc1-a-xnas001.adm.example.net -server-enabled true -client-enabled false # 6. Verify security ssl show # --- Data SVM: new self-signed certificate, valid ten years ------------------- # 7. Create the certificate certificate create -common-name DC1-S-VCVSM001 -type server -size 2048 -country <COUNTRY_CODE> -locality <LOCALITY> -organization "Example Org" -email-addr admin01@example.net -expire-days 3652 -vserver DC1-S-VCVSM001 # 8. Delete the old certificate of the SVM certificate delete -serial <OLD_CERT_SERIAL> * # 9. Point the web service of the SVM at the new certificate and verify security ssl modify -server-enabled true -vserver DC1-S-VCVSM001 -common-name DC1-S-VCVSM001 -serial <CERT_SERIAL> -ca DC1-S-VCVSM001 security ssl show -vserver DC1-S-VCVSM001 -instance
Differences between the runs:
| Run | Common name | E-mail in the subject |
|---|---|---|
DC1-A-XNAS001 | dc1-a-xnas001.adm.example.net | admin01@example.net |
DC1-B-XNAS001 | dc1-b-xnas001.adm.example.net | admin01@example.net |
| SVMs 001, 003, 004 | name of the SVM | admin01@example.net |
| SVMs 002, 006, on 8 July 2019 | name of the SVM | infra.security@example.net |
For the cluster certificates issued in 2019 the design lists a shared mailbox in the subject (security@example.net, for the site 2 clusters infra.security@example.net) and an organisational unit, which the commands of 2017 do not have. The first requests carried a personal address, which is one more thing that outlives the person.
The notes do not show the old cluster certificate being deleted after step 5, nor the CA certificate being installed as a chain; the prompt in step 3 was answered with n.
Checked against ONTAP 9.19.1
| As built | Today |
|---|---|
security certificate generate-csr … -size 2048 | Valid. -size is deprecated since ONTAP 9.8 in favour of -security-strength. New options: -algorithm (RSA or EC), -hash-function (default SHA256) and subject alternative names (-dns-name, -ipaddr, -uri, -rfc822-name) |
| Request without subject alternative name | The as-built requests carried none; a request can now carry them |
security certificate install -vserver … -type server | Valid; adds -cert-name |
security certificate create … -expire-days 3652 | Valid. -expire-days takes 1 to 3652, the default is 365 |
security ssl modify -ca … -serial … -common-name … | Valid; adds OCSP options |
The procedure is unchanged in its steps. A request made today should carry the DNS name as a subject alternative name. Ten years remains the maximum for a self-signed certificate, not a recommendation.