Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NSX-T Manager Certificate Creation Does Not Include IP SAN #1334

Open
lancefrench opened this issue Jul 1, 2021 · 2 comments
Open

NSX-T Manager Certificate Creation Does Not Include IP SAN #1334

lancefrench opened this issue Jul 1, 2021 · 2 comments

Comments

@lancefrench
Copy link
Contributor

In nsxt-3-0-install.html.md.erb we specify a certificate configuration file and certificate generation command generates a certificate without a Subject Alternative Name despite our intention to do so.

Once we specify the openssl x509 command, the req_extensions section of our configuration, which includes the SAN, is ignored.

@cf-gitbot
Copy link
Member

We have created an issue in Pivotal Tracker to manage this. Unfortunately, the Pivotal Tracker project is private so you may be unable to view the contents of the story.

The labels on this github issue will be updated when the story is started.

@lancefrench
Copy link
Contributor Author

Busted as of 2da9754 I suggest copying the subjectAltName configuration under the SAN section if v3_ca is necessary per the "engineering feedback" or reverting the configuration to a previous working version.

Happy to submit a pull request if there's more context on the engineering feedback.

@lancefrench lancefrench changed the title NSX-T Manager Certificate Creation Does Not Include SAN NSX-T Manager Certificate Creation Does Not Include IP SAN Jul 2, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants