Review the requirements and limitations for managing custom Secure Sockets Layer (SSL) certificates and certificate-based authentication.
Custom certificate configuration manages SSL certificates and private keys that secure communication with the Cisco APIC cluster.
Configuration guidelines and limitations
Observe the following guidelines and limitations when you configure custom certificates:
-
You cannot export a private key that was used to generate a certificate signing request (CSR) on the Cisco Application Policy Infrastructure Controller ( APIC ). To use the same certificate on multiple servers, generate the private key outside the Cisco Application Centric Infrastructure ( ACI ) fabric and import the key.
-
Download and install the public intermediate and root certificate authority (CA) certificates before you generate a CSR. This sequence prevents a mismatch between the intended CA and the CA that signs the certificate.
-
To reuse the public and private keys when you renew a certificate, retain and resubmit the original CSR. Do not delete the original key ring.
-
Cisco ACI Multi-Site , VCPlugin, VRA, and SCVMM do not support certificate-based authentication.
-
Each Cisco APIC cluster supports only one SSL certificate.
-
Disable certificate-based authentication before you downgrade to Release 4.0(1).
-
To terminate a certificate-based authentication session, log out and remove the common access card (CAC).
-
Custom certificates are deployed to leaf and spine switches. To cover the fabric nodes, include the URL or distinguished name (DN) in the Subject or Subject Alternative Name field.
-
The Cisco APIC GUI accepts certificates with a maximum size of 4 KB.
-
Self-signed SSL certificates that are used for HTTPS access renew automatically when they expire.