Users Guide

Table Of Contents
Automatic Certificate Enrollment
In iDRAC, Automatic certificate enrollment feature enables you for automatic installation and renewal of certificates used by the
web server. When this feature is enabled, the existing web server certificate is replaced by a new certificate.
NOTE:
Automatic certificate enrollment is a licensed feature and requires Datacenter license.
Valid NDES (Network Device Enrollment Service) setup is required for issuing the server certificate.
Following are the automatic certificate enrollment configuration parameters:
Enable / Disable
SCEP server URL
Challenge password
NOTE: For more information on these parameters, see iDRAC Online Help.
Following are the available status for Automatic certificate enrollment:
Enrolled - Automatic certificate enrollment is enabled. Certificate is monitored and new certificate can be issued on expiry.
Enrolling - Intermediate state after Automatic certificate enrollment is enabled.
Error - Problem encountered with NDES server.
None - Default.
NOTE: When you enable Automatic certificate enrollment, web server is restarted and all existing web sessions are logged
out.
Uploading server certificate
After generating a CSR, you can upload the signed SSL server certificate to the iDRAC firmware. iDRAC must be reset to apply
the certificate. iDRAC accepts only X509, Base 64 encoded Web server certificates. SHA-2 certificates are also supported.
CAUTION: During reset, iDRAC is not available for a few minutes.
Uploading server certificate using web interface
To upload the SSL server certificate:
1. In the iDRAC Web interface, go to iDRAC Settings > Connectivity > SSL > SSL certificate, select Upload Server
Certificate and click Next.
The Certificate Upload page is displayed.
2. Under File Path, click Browse and select the certificate on the management station.
3. Click Apply.
The SSL server certificate is uploaded to iDRAC.
4. A pop-up message is displayed asking you to reset iDRAC immediately or at a later time. Click Reset iDRAC or Reset
iDRAC Later as required.
iDRAC resets and the new certificate is applied. The iDRAC is not available for a few minutes during the reset.
NOTE: You must reset iDRAC to apply the new certificate. Until iDRAC is reset, the existing certificate is active.
Uploading server certificate using RACADM
To upload the SSL server certificate, use the sslcertupload command. For more information, see the iDRAC RACADM CLI
Guide available at https://www.dell.com/idracmanuals.
If the CSR is generated outside of iDRAC with a private key available, then to upload the certificate to iDRAC:
1. Send the CSR to a well-known root CA. CA signs the CSR and the CSR becomes a valid certificate.
2. Upload the private key using the remote racadm sslkeyupload command.
3. Upload the signed certificate to iDRAC using the remote racadm sslcertupload command.
The new certificate is uploaded iDRAC. A message is displayed asking you to reset iDRAC.
Configuring iDRAC
109