1 Rookie
•
25 Posts
0
967
August 9th, 2021 03:00
idrac 7 and wildcard certificate problems
Hello,
I have created a certificate with a wildcard '*.domain.com' which is a 2048 bit. I then extracted the key and crt and then uploaded these to the idrac using racadm command also reset the card after that.
When I browse to the idrac however, I still see the 'Not Secure' shown.
If I select and view the cert, it looks good, no errors. This needs to be rolled out to around 70 devices.
This is on PW720XD running Windows 2016 DC and I am on the latest firmware (2.65.65.65 (Build 15)).
Is there something I am missing?
No Events found!
Latif
1 Rookie
•
25 Posts
1
August 10th, 2021 07:00
Hi,
We have now fixed this by adding *.domain.com as SAN certificate.
I was not aware this needed to be done, but it fixed the issue.
Thanks
DELL-Shine K
4 Operator
•
3K Posts
0
August 9th, 2021 04:00
Can you share picture of error shown and also share the operating system and browser used to launch iDRAC?
Can you also confirm whether
Latif
1 Rookie
•
25 Posts
0
August 9th, 2021 05:00
Hi,
I am using Chrome to browse to the site. As soon as iDRAC login screen loads, I see the 'Not Secure' displayed.
When I view the cert, I do not see any issues.
Happy to try anything else you may suggest.
Thanks
DELL-Shine K
4 Operator
•
3K Posts
0
August 9th, 2021 18:00
Can you confirm address you used to launch iDRAC is matching with wildcard certificate you uploaded to iDRAC. E.g. If you have '*.domain.com' in certificate then you should be launching iDRAC with hostname/FQDN which ends with '.domain.com' E.g. test.domain.com. Certificate error will be shown if you launch with IP address or hostname not matching with Common name configured on certificate.
Can you also ensure CA certificate (of CA where you got iDRAC certificate signed) is uploaded to the Trusted Root Certificate Authorities section of your client certificate store
If above 2 step is not matching then certificate error will be displayed on the browser
Latif
1 Rookie
•
25 Posts
0
August 10th, 2021 06:00
Hi,
Yes, we use idrac name as servername-idrac.domain.com and browse to this as https://servername-idrac.domain.com. (Not using the IP address).
I have also added the cert in to Trusted Root Certificate Authorities. Unfortunately Browsing from Chrome or Edge brings the same error:
No issues when viewing the certificate:
DELL-Shine K
4 Operator
•
3K Posts
0
August 10th, 2021 07:00
Great to hear that issue is resolved. Yes For chrome browser I believe there is a check at SAN level also.