Building an SDDC following VMware’s Validated Designs, when adding vRealize Network Insight to the mix, it is possible to use the CertGenVVD tool to generate custom SSL certificates and install them to vRealize Network Insight.
Caveat – I assume you are familiar with the CertGenVVD tool and process!
Process to Generate Custom SSL Certificate and Install
- Copy the existing vrops certificate template text file to vrni.txt
- Update vrni.txt CN to the vRNI platform VM FQDN
- Add the vRNI platform VM FQDN, short name, and IP to the SAN section
- Generate the certificate using the CertGenVVD PowerShell script
- Copy the public key full chain “vrni.crt” and place on a secure Linux system accessible to vRNI platform VM
- When using 2-tier PKI, make sure to append the root CA public key to the end of the …chain.pem file generated by CertGenVVD
- Copy the private key to “vrni.key” on the same system (make sure to delete these files securely after completing all the steps here)
- Log in to vRNI platform using the CLI user (consoleuser, see default password)
- Follow the directions in this KB: https://kb.vmware.com/kb/2148128
- In the custom-cert command, the “host” is the Linux system where you copied the generated key files
- Verify by navigating to the platform VM URL
Note: Leaving out the fqdn in the SAN section caused Google Chrome to fail validation, although Internet Explorer 10 validated the cert with no issue.
Hope this helps.