Comprehensive data protection for all workloads
Post Reply
Loosus456
Novice
Posts: 9
Liked: 3 times
Joined: Sep 29, 2021 12:22 pm
Full Name: Jason
Contact:

Automating certificate renewal for web UI (TCP 443) on Veeam Software Appliance?

Post by Loosus456 » 2 people like this post

We use Let's Encrypt along with the DNS-01 challenge to renew our wildcard certificate (*[.]example[.]com) every 45 days. We have a virtual machine that takes care of the wildcard renewal, retrieves the new wildcard files and private keys, stores the new wildcard files, and runs an SFTP server that serves the certificate files to other servers that need them. For security purposes, servers that need the certificate files reach out to the certificates VM rather than the certificates VM reaching out to them.

We need to rotate the web UI certificate every 45 days (or more often). We need to automate rotation because manual replacement obviously isn't really a thing these days.
  1. Can I store a simple bash script on the Veeam Software Appliance to retrieve the wildcard certificate from our certificates VM? If so, is there a preferred directory path where I should store it?
  2. Can I run a cron job on VSA under the root account?
  3. Will VSA updates/upgrades eventually blow away our bash script and cron job? If so, is there a way to prevent that from happening?
  4. Assuming I can put a bash script and associated cron job on the VSA server, which certificate file and private key file do I need to have the bash script replace/rotate? What is the directory path to those files? After replacement, do any services/daemons need to be restarted for the replacement to take effect?
Mildur
Product Manager
Posts: 12141
Liked: 3479 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Automating certificate renewal for web UI (TCP 443) on Veeam Software Appliance?

Post by Mildur »

Hi Jason,

Running scripts or applying custom settings on our appliances is not supported: KB 4772.

This includes running custom scripts or changing cron jobs.

We have a PowerShell cmdlet (Add-VBRBackupServerCertificate) to replace the backup server certificate, but it still requires a backup service reboot, which cannot be done for the appliance over PowerShell or REST API.

Right now, there is no supported solution for your use case, but we are thinking about options to allow automated certificate installation.

Until we deliver such a feature, either stay on a Windows-based backup server, where you can script almost anything, or use VSA and manually replace the certificate whenever needed.

Best,
Fabian
Product Management Analyst @ Veeam Software
Post Reply

Who is online

Users browsing this forum: Amazon [Bot], Google [Bot], k.terui, Semrush [Bot] and 318 guests