Start a Conversation

Solved!

Go to Solution

1 Rookie

 • 

25 Posts

967

August 9th, 2021 03:00

idrac 7 and wildcard certificate problems

Hello,

I have created a certificate with a wildcard '*.domain.com' which is a 2048 bit. I then extracted the key and crt and then uploaded these to the idrac using racadm command also reset the card after that. 

When I browse to the idrac however, I still see the 'Not Secure' shown.

If I select and view the cert, it looks good, no errors. This needs to be rolled out to around 70 devices.

This is on PW720XD running Windows 2016 DC and I am on the latest firmware (2.65.65.65 (Build 15)).

Is there something I am missing?

1 Rookie

 • 

25 Posts

August 10th, 2021 07:00

Hi,

 

We have now fixed this by adding *.domain.com as SAN certificate. 

I was not aware this needed to be done, but it fixed the issue.

 

Thanks

4 Operator

 • 

3K Posts

August 9th, 2021 04:00

Can you share picture of error shown and also share the operating system and browser used to launch iDRAC?

Can you also confirm whether

  • root CA certificate is uploaded to the browser trusted CA 
  • address used to launch iDRAC is matching with wildcard name given on the certificate

1 Rookie

 • 

25 Posts

August 9th, 2021 05:00

Hi,

I am using Chrome to browse to the site. As soon as iDRAC login screen loads, I see the 'Not Secure' displayed.

When I view the cert, I do not see any issues.

Latif_0-1628511300566.png

Happy to try anything else you may suggest.

Thanks

4 Operator

 • 

3K Posts

August 9th, 2021 18:00

Can you confirm address you used to launch iDRAC is matching with wildcard certificate you uploaded to iDRAC. E.g. If you have  '*.domain.com' in certificate then you should be launching iDRAC with hostname/FQDN which ends with  '.domain.com' E.g. test.domain.com. Certificate error will be shown if you launch with IP address or hostname not matching with Common name configured on certificate. 

Can you also ensure CA certificate (of CA where you got iDRAC certificate signed) is uploaded to the Trusted Root Certificate Authorities section of your client certificate store 

If above 2 step is not matching then certificate error will be displayed on the browser

1 Rookie

 • 

25 Posts

August 10th, 2021 06:00

Hi,

Yes, we use idrac name as servername-idrac.domain.com and browse to this as https://servername-idrac.domain.com. (Not using the IP address).

I have also added the cert in to Trusted Root Certificate Authorities. Unfortunately Browsing from Chrome or Edge brings the same error:

Latif_0-1628600822838.png

 

No issues when viewing the certificate:

Latif_1-1628600911341.png

 

4 Operator

 • 

3K Posts

August 10th, 2021 07:00

Great to hear that issue is resolved. Yes For chrome browser I believe there is a check at SAN level also.

No Events found!

Top