Replacing Certificates on Storage Systems
When a storage system communicates with external devices, you are advised to verify certificates for enhanced security. This section describes how to generate and export signature requests and how to import and activate signed certificates.
Procedure
- Log in to DeviceManager.
- Choose Settings > Certificate Management.
- Select the type of certificate you want to export and click Export Request File. Specify the Certificate Key Algorithm and click OK.
- Import and activate the signed certificate.
- Send the certificate request file to a certificate authority or sign it with an enterprise root certificate. After the certificate is signed, click Import Certificate on DeviceManager.
The Import Certificate dialog box is displayed.
- Configure the certificate parameters listed in Table 12-8.
- Click OK.
A security alert dialog box is displayed.
- Confirm the information in the dialog box and select I have read and understand the consequences associated with performing this operation. Then click OK.
The Success dialog box is displayed.
- Click OK.
The certificate list shows imported certificates.
The CA certificate is not displayed in the certificate list.
- Send the certificate request file to a certificate authority or sign it with an enterprise root certificate. After the certificate is signed, click Import Certificate on DeviceManager.
- View the certificate information. Table 12-9 describes the parameters.Table 12-9 Certificate parameters
Parameter
Description
Scenario
Scenario where a certificate is used.
Expiration Warning Days
Days before certificate expiration. When the period starts, the system sends warning to users about the expiration.
NOTE:The value ranges from 7 to 180.
Client Certificates
Number of client certificates.
CA Certificates
Number of CA certificates.
Certificate Revocation Lists
Number of certificate revocation lists.
NOTE:You can view certificate revocation lists to check the CA certificate availability.
- Modify a certificate.
- Select a certificate that you want to modify and click Modify.
The Modify dialog box is displayed.
- Modify the certificate parameters listed in Table 12-10.
Table 12-10 Certificate parameters
Parameter
Description
Expiration Warning Days
Days before certificate expiration. When the period starts, the system sends warning to users about the expiration.
NOTE:The value ranges from 7 to 180.
New Private Key Encryption Password
New encryption password for private key files.
Confirm Password
Password confirmation.
- Click OK.
The Success dialog box is displayed.
- Click OK.
- Select a certificate that you want to modify and click Modify.
- Manage Certificate Revocation Lists (CRLs).
- Import a CRL.
- Click Import Revocation List.
- In the dialog box that is displayed, select a CRL file and click OK.
- Confirm the information in the dialog box and select I have read and understand the consequences associated with performing this operation.
- Click OK.
A dialog box is displayed indicating that the operation is successful.
- Query the CRLs.
Click the name of a certificate under Scenario and query the certificate details.
- Import a CRL.