Comprehensive data protection for all workloads
Post Reply
dojit
Novice
Posts: 9
Liked: 2 times
Joined: Sep 06, 2018 4:15 am
Full Name: Steve Harris
Contact:

Host Management Console port 10443 Certificate Signed by Internal CA

Post by dojit »

Moderator split from viewtopic.php?p=556649#p556649

Hi All,

Our VEEAM host management console on port 10443 is reporting OOTB "Not Secure", using the self-signed VEEAM cert.

We seek to use our internal Microsoft PKI as per "Using Certificate Signed by Internal CA"
https://helpcenter.veeam.com/docs/vbr/u ... +ca&ver=13

However, we have a two-tier Microsoft PKI design (Offline Root CA and Enterprise online Subordinate Issuing CA)

The Path Length Constraint parameter must be set to 0.
Duplicating the Subordinate Certification Authority Template, creating the .inf, certreq new, certreq submit fails.

I'm assuming this means VEEAM only supports a single-tier Root CA.

Thanks,

Steve
HannesK
Product Manager
Posts: 16396
Liked: 3759 times
Joined: Sep 01, 2014 11:46 am
Full Name: Hannes Kasparick
Location: Austria
Contact:

Re: Host Management Console port 10443 Certificate Signed by Internal CA

Post by HannesK »

Hello,
for the Host Management Console you can just use a regular TLS server certificate and the link does not apply. That link is for the internal CA where the backup server signs certificates for agents etc.

Best regards
Hannes
Post Reply

Who is online

Users browsing this forum: Semrush [Bot] and 278 guests