UCS Manager and using Microsoft Certificate Authority

Everyone crossed by the configuration process UCS Manager with a certificate issued by a Microsoft certification authority?  If yes I would appreciate some help.  I was able to create a request and have generated the certificate successfully, but I see no way to be able to get back the request and the certificate chain in the UCS Manager.

First you must create a trust (on the Admin-> Key Management tab). In the new trust point, paste public cert in your root certification authority base64 format. If you have a subordinate certification authority that brings then add cert that CA too. If you have a whole tree of certification authorities, then you should create a point of trust with any of the string of the issueing CA to the root. Paste a cert after the other, in order, the string, all in the same point of trust. If they are not in the right order, or if you are missing the root, then the TP does not accept the cert.

Once you have a trust, you can accept the certificate that you generated. In the Keyring, you used to generate the request, select the new Point of confidence and paste the new certificate in Base64 format into the field of the certificate.

Once this is done, you can go to the Directorate of Communication-> the Communication Services and for HTTPS, select the new key ring. It might not take effect immediately, but after a few minutes your web site UCSM should begin to answer with the new certificate.

I hope this helps.

Note: There is a bug in UCS currently send number CSCth62582. If your fabric interconnects fail, the SSL certificate will return to the default self-signed cert. You must go back in Communication services and set it to default, save it, and then assign the new ring of keys.

Tags: Cisco DataCenter

Similar Questions

  • 2011 Microsoft certificate authority certificate installation

    I need to install the Microsoft 2011 certificate authority certificate. I installed the certificate, then checked the Certificates snap in MS Management Console and the Microsoft certificate authority 2011 certificate was not there.

    I want to use method 4. https://support.Microsoft.com/en-us/KB/3149737.

    Thank you!

    Post proposed by the facilitator for the appropriate forum placed

    This issue is beyond the scope of this site (for consumers) and to make sure you get the best answer, we need to ask either on Technet (for IT Pro) or MSDN (for developers)

    If you give us a link to the new thread we can point to some resources it
  • Can I install and use microsoft security essentials in domain system

    Hello
    my system is added to the domain, I will use without any problem of conpatable?
    are you propose me to use in these condetions?

    Hi Ram,

    Thanks for visiting the site of the community of Microsoft Windows XP. The question you have posted is related to the areas and would be better suited to the Technet community. Please visit the link below to find a community that will provide the support you want.

    http://social.technet.Microsoft.com/forums/en-us/categories/ Shawn - Support Engineer - MCP, MCDST
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • Watch Vista Task Manager (and use) 3 4 GB

    Hi all!

    Vista Home Premium 64-bit () show that my laptop has 4 GB of RAM, but the Task Manager shows only 3 GB.

    Any ideas on that?

    It will be nice to use the last 1 GB "reserved".

    Thanks in advance.

    the Z61m is based on the chipset intel 945 and unfortunately can only use 3 GB maximum regardless of the operating system or of the amount of memory installed.   what you see, it's normal.

  • Can I see faults offset and deleted in the UCS Manager?

    Is there a way to see the flaws that have been deleted in the UCS Manager and deleted once the retention period has expired?

    Thank you.

    .. .Brian

    No, unless you use an external syslog server.  It is the only way to maintain indefinitely offset flaws.

    Robert

  • How can I restrict access to programs and use between different users?

    I have various users defined in the system. While I I want all users to be able to access and use Microsoft Word, there are some other proprietary programs that must be available for some users: me and my manager and staff. Of course, the administrator can access and be able to use all the programs defined for Windows.

    It is for one computer only?  Or a wide area?  Using XP Professional?

    For a single machine (XP Pro) you can only use NTFS permissions and share permissions on the folder for the specific program or for the executable file for the specific user or groups of users.  Just right click on the object and select Properties, then click the Security tab.  It is best to apply permissions to groups rather than to individual users, you then control access of the user by their membership to a group, it makes it much easier to manage permissions and avoids headaches down the road.

    You can create new groups of users for your own needs.  For example, suppose you have an accounting software that should only be accessed by Mary and Jim, who are in charge of accounting.  You can create a group called accounting and that Marie and Jim in the Group and only allow the accounting group to have access to accounting software.  If the latter you hire someone else to do the work of accounting you make the new person member of the accounting of the Group and he will have access to the software.  You could do the same with software engineering, you can create a group called engineers with authorization on software engineering and give membership to your engineers.

    You can also do this with data files, lets say you have junior engineers and experienced engineers, they all use the same software, so they all need to be in the Group of engineers.  But engineers are working on secret projects that subordinate engineers should not have access to.  You can simply store the data for secret projects files in a different folder and create a group called Secret and only the mechanics leading members of this group.

    John

  • UCS FI and iSCSI storage

    We are poised to implement a UCS B Series. I have a question for FI 6248UP. I have read and used the emulator for UCS Manager and noticed that you can configure ports FI as ways for storage material. Is it limited to a certain protocol storage or the seller? We use Dell EQ and plan to be there to connect the EQ 6510 X. I was wondering if that is supported and if iSCSI upstream traffic would be able to access the storage?

    The 6248UPs will be passed to a pair of Catalyst 4506-E race vs. We have an IBM chassis and servers should be able to access the EQ6510X too. I guess I just need master iSCSI VLANS for the 6248UP and the servers would have access?

    Thank you!

    Hi Cowetac,

    Yes, not all storage arrays are supported by UCS, but your DELL Equalogic is supported. If you have any questions about the other compatibility of storage arrays, you can take a look at the UCS (see link below) storage interoperability matrix.

    UCS storage interoperability Matrix (matrix of the storage of UCS - B of table 10-2)

    http://www.Cisco.com/en/us/docs/switches/Datacenter/MDS9000/interoperability/matrix/Matrix8.html

    I guess I just need master iSCSI VLANS for the 6248UP and the servers would have access?

    Depends, if you use one port of the device the UCS for you connect directly to storage, you can use a single vlan.

    If you are connected via the Ethernet uplinks via a switch, you need to set your switches as a trunk port.

  • UCS Manager - internal backup system failed [WSF: FAILURE]

    Hello

    I have UCS Manager Version 2.2 (1 c)

    I implemented the backup of the configuration via SCP and Im getting error.

    Destination is accessible from other computers in the same VLAN via WinSCP.

    I need help what exactly is causing that error in the UCS Manager and how to solve this problem.

    I tried to delete and add new functioning of the backup operation.

    Severity: critical
    [FWS: FAILURE]: internal system backup
    Type: WSF
    Cause: WSF-failed
    Code: F999723

    I'm waiting to activate fast playback.

    See you soon.

    Looking at the logs you posted there is an inconsistency in the algorithms between scp server and the ucs system. Server accepts the aes - ctr and ucs uses aes - cbc?
    Maybe try adding

    "The cipher aes128-ctr, aes192-ctr, aes256-ctr, aes128-cbc" to/etc/ssh/sshd_conf

  • 'Need permission to use microsoft online services' cannot open a session!

    That's what I get by trying to connect to msn or hotmail:

    You need permission to use Microsoft online services.

    Before you can log in and use Microsoft online services, a parent must give you permission. You can get permission right now by asking your parents to come to the computer. Or, you can send an e-mail asking their permission to your parents.

    After your mother gives you permission, you can sign in with your new e-mail address, * address email is removed from the privacy *.

    Parent: To give or deny your child to sign in and use Microsoft online services, click Get Permission Now.

     

      

     

    If I click on "I am an adult" it shows date of birth can be a problem but I can't check and it also asks that the credit card age verification? !!  Thanks for your help!

    Hi Kopatch,

    See the links below to learn more about the cause.

    Any age-based consent
    http://help.MSN.com/ (cHJvamVjdD1wYXNzcG9ydDQmbWFya2V0PWVuLXVz)/Help.aspx?market=en-US&project=Passport4&querytype=topic&query=Accountv1_CONC_AboutAgeBasedConsent.htm

    Right to a request to create a Windows Live ID a child
    http://help.MSN.com/ (cHJvamVjdD1wYXNzcG9ydDQmbWFya2V0PWVuLXVz)/help.aspx?querytype=topic&query=accountv1_proc_addchild.htm

    http://windowslivehelp.com/community/p/146423/531050.aspx

    Halima S - Microsoft technical support.
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Upgrade of the UCS Manager

    Hi all

    I have my UCS Manager and I need to do an upgrade, my question is the VMS, I executed what I need to move them from one device to the other? or I can do the upgrade with no downtime?

    Can someone give me a procedure on how I do this?

    Thank you all.

    Hello

    An upgrade is usually done in two parts:

    (1) infrastructure (IOM, UCSM, fabric interconnection networks)

    (2) blades (BIOS, adapters, CIMC, Controller Board, Flexflash, etc.)

    During upgrade infrastructure, you will need to restart the fabric connects one at a time. When you make one of your two fabrics will be down for about 20 minutes. If you have redundant vNIC/vHBAs in all of your tissues A and B, it should ask only degraded services in the environment. However, a maintenance window is always recommended. When you upgrade the blades, you will need to restart. This is probably where you should move your virtual machines. After that you upgrade the blades make sure you update your OS drivers as well!

    UCS firmware update as follows:

    http://www.Cisco.com/c/en/us/support/servers-unified-computing/UCS-manag...

    Download the firmware:

    https://software.Cisco.com/download/release.html?mdfid=283853163&flowid=...

    Compatibility matrix:

    http://www.Cisco.com/c/en/us/support/servers-unified-computing/unified-c...

    I hope this helps.

    Justin

  • How to match tunnel-group with auth ASA 8.2 and IPSec VPN Client using digital certificates with Microsoft CA

    Hello

    I set up a lab for RA VPN with a version of the ASA5510 8.2 and VPN Client 5 software using digital certificates with Microsoft CA on a Windows 2003 server. I did the configuration based on this document from Cisco's Web site:

    http://www.Cisco.com/en/us/partner/products/ps6120/products_configuration_example09186a0080930f21.shtml

    Now, the vpn works fine, but now I need to configure a tunnel-different groups so I can provide different services to different users. The problem I have now is that I don't know how to set it up for the certificate is the name of tunnel-group. If I do an ASA debug crypto isakmp I get this error message:

    % ASA-713906 7: IP = 165.98.139.12, trying to find the group through OR...
    % 3 ASA-713020: IP = 165.98.139.12, no group found by matching well payload ID: unknown
    % ASA-713906 7: IP = 165.98.139.12, trying to find the group via IKE ID...
    % 3 ASA-713020: IP = 165.98.139.12, no group found by matching well payload ID: unknown
    % ASA-713906 7: IP = 165.98.139.12, trying to find the group via IP ADDR...
    % ASA-713906 7: IP = 165.98.139.12, trying to find the group using default group...
    % ASA-713906 7: IP = 165.98.139.12, connection landed on tunnel_group DefaultRAGroup

    So, basically, when using certificates I connect always VPN RA only with the group default DefaultRAGroup. Do I have to use a model of different web registration for application for a certificate instead of the user model? How can I determine the OU on the user certificate so that match tunnel-group?

    Please help me!

    Kind regards

    Fernando Aguirre

    You can use the group certificate mapping feature to map to a specific group.

    This is the configuration for your reference guide:

    http://www.Cisco.com/en/us/partner/docs/security/ASA/asa82/configuration/guide/IKE.html#wp1053978

    And here is the command for "map of crypto ca certificate": reference

    http://www.Cisco.com/en/us/docs/security/ASA/asa80/command/reference/C5.html#wp2186685

    Hope that helps.

  • AnyConnect VPN Microsoft CA and a Public certificate

    Hello

    I'm looking for some help with a script. I'm no expert in networks by any stretch and I won't implement myself but I need to try to understand if it is possible what I'm looking for.

    We are implementing an Anyconnect VPN with certificate of our own internal CA of Microsoft authentication. I have a product which will distribute certificates from a model for mobile devices rather than the SAA itself. We have our CA and a certificate of identity on the SAA and the operation of the authentication.

    However, the IOS Anyconnect application complains that no reliable VPN.

    So from there, I get that I need a public certificate on the SAA, but can I still have the certificate of the Microsoft CA and certificate of identity making the authentication of end users?

    Can I have written some of it wrong, but I think this gives an idea where I'm going.

    Pointers would be greatly appreciated.

    Yes - IOS is somewhat capricious won't trust internal CA issued certificates. You can buy and install a certificate from a well known public certification authority and to identify your ASA. That will be the certificate bound to the ASA outside interface and it will allow the customers based on IOS (and all others) to connect using this certificate.

    This part is distinguished by the device or user certificates on clients. Those who can still be used, as long the ASA has imported the Microsoft CA on trusts and the public key of the server, the two can co-exist.

  • Firewall Windows with advanced security and mmc microsoft management console

    I want to know how to run the MMC snap-in. You load them in the tree of the Console at all times? The center column takes them and then what? This thing is huge and I can't find any questions about it on the community boards. I mean, REALLY, it is complex, and I'm sure that most people do not know how it works. Microsoft Management Console. Snap ins someone explain this - start with - that is meant by the snap ins all about and how to use them. Microsoft has a video to watch? Explain the purposes and uses. And how it relates to Windows Firewall with advanced security?
    I just had a "Nerd" pro retrieves a hacker to my machine. The pirate had resumed MMC and Windows Firewall. I want to learn this now.

    Hello

    Thanks for the display of the query to the Microsoft Community. If I understand correctly, you want to learn more about the Microsoft Management Console.

    You can go through the article and check. Here is another article on the Microsoft Management Console. You can navigate on the article for more information about MMC. Here is some additional information on the addition of the software component Certificates snap-in to an MMC.

    You can also view the request here.

    Hope this information was helpful and let us know if you need help in the future about Windows. We will be happy to help you.

  • How do I configure the iPad2 to synchronize the iPad-Mailclient with Exchange 2010 via Active Sync using the certificate SSL client and name of user and password?

    Active Sync iPad ssl Client certificate

    How do I configure the iPad2 to synchronize the iPad-Mailclient with Exchange 2010 via Active Sync using the certificate SSL client and name of user and password?

    Hi Ewoki,

    Your question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the TechNet Exchange forum. Please post your question in the Forums TechNet in Exchange Server.

  • Windows Movie Maker "the file is protected using digital rights management and cannot be imported."

    I downloaded a large .wmv file last night and have to divide into 8 smaller parts, but when I try to "import media" in Movie Maker is stipulates that "the file is protected using digital rights management and cannot be imported.

    Is it possible to import the file to edit?

    Turnbite removes the DRM http://download.cnet.com/Tunebite/3000-2140_4-10783040.html but I still don't know if it would work with Movie Maker (only because I haven't used products - looks like it would work, but I'm not sure).  Here is a review of version 6 (the current version is 7): http://mp3.about.com/od/audiotools/fr/Tunebite_6_Rev.htm.  Apparently, he's copying your DRM files and so it is required to have at least some degradation (but not a lot from what I've read - not noticeable).  Because it's free, it can't hurt to try it and see if it solves the problem.

    AVS looks like he got a number of good products http://www.avsmedia.com/, but I don't think that one of them address the DRM issue.  I really didn't listen to music or watch videos on my PC very often so I'm not familiar with the products to do such things.  May I suggest you post your question in the music and its Forum: http://social.answers.microsoft.com/Forums/en-US/vistamedia/threads , where issues of music specialists will be more than happy to help you with your questions.   Or in the photos and video Forum at: http://social.answers.microsoft.com/Forums/en-US/vistapictures/threads where the video specialists will be happy to help with you project of filmmaking.

    As for Shane Childs, I suspect that Karthik copied an answer, he used for this person to respond to your question and everything just forgot to change the username - just a typing error.

    Good luck and I hope this helps. Lorien - a - MCSE/MCSA/network + / A +.

Maybe you are looking for

  • ITunes cards

    How can I buy a card Pakistan to iTunes and buy in Pakistani AppStore please help

  • Problems with the Satellite A-210 camera

    Hello. I have a problem with my webcam, sometimes it's not ok. Sometimes I can use in the Messenger, but sometimes show me a problem and I can't use it. Display a message as I am using the camera in another program but is not fair. Can you help me? I

  • Integration of Skype Outlook 2013

    I have the latest version of Skype (6,7) installed and works, but this isn't the integration with Outlook. I found another article saying that you may need to change the default application of IM to Skype of Lync. However, in my list of instant messa

  • Backup using Time Machine on two external drives?

    I know that time the machine supports two separate discs, but my question is: For example: If I have a Pegasus RAID of 8 TB, can I use two external 4 TB to my time machine backup disks? Time machine splits my data through the two HD? Thank you!

  • HP Probok 450 G2: Misssing of Windows 7 drivers

    Hello I have a problem with these two unknown devices: ACPI\HPQ6007 ACPI\INT33A0 You can send a link to download the missing drivers? Concerning Michael