Skip to content

Commit 5da1297

Browse files
authored
Merge pull request #67727 from mjpytlak/ocpbugs-19368
OCPBUGS#19368: Added guidance on internal CA
2 parents 0c5f9c5 + 8803b44 commit 5da1297

File tree

2 files changed

+4
-0
lines changed

2 files changed

+4
-0
lines changed

installing/installing_nutanix/installing-nutanix-installer-provisioned.adoc

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,8 @@ In {product-title} version {product-version}, you can install a cluster on your
2222
** You configured the firewall to xref:../../installing/install_config/configuring-firewall.adoc#configuring-firewall[grant access] to the sites that {product-title} requires. This includes the use of Telemetry.
2323
* If your Nutanix environment is using the default self-signed SSL certificate, replace it with a certificate that is signed by a CA. The installation program requires a valid CA-signed certificate to access to the Prism Central API. For more information about replacing the self-signed certificate, see the https://portal.nutanix.com/page/documents/details?targetId=Nutanix-Security-Guide-v6_1:mul-security-ssl-certificate-pc-t.html[Nutanix AOS Security Guide].
2424
+
25+
If your Nutanix environment uses an internal CA to issue certificates, you must configure a cluster-wide proxy as part of the installation process. For more information, see xref:../../networking/configuring-a-custom-pki.adoc#configuring-a-custom-pki[Configuring a custom PKI].
26+
+
2527
[IMPORTANT]
2628
====
2729
Use 2048-bit certificates. The installation fails if you use 4096-bit certificates with Prism Central 2022.x.

installing/installing_nutanix/installing-restricted-networks-nutanix-installer-provisioned.adoc

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,8 @@ In {product-title} {product-version}, you can install a cluster on Nutanix infra
1717
** You configured the firewall to xref:../../installing/install_config/configuring-firewall.adoc#configuring-firewall[grant access] to the sites that {product-title} requires. This includes the use of Telemetry.
1818
* If your Nutanix environment is using the default self-signed SSL/TLS certificate, replace it with a certificate that is signed by a CA. The installation program requires a valid CA-signed certificate to access to the Prism Central API. For more information about replacing the self-signed certificate, see the https://portal.nutanix.com/page/documents/details?targetId=Nutanix-Security-Guide-v6_1:mul-security-ssl-certificate-pc-t.html[Nutanix AOS Security Guide].
1919
+
20+
If your Nutanix environment uses an internal CA to issue certificates, you must configure a cluster-wide proxy as part of the installation process. For more information, see xref:../../networking/configuring-a-custom-pki.adoc#configuring-a-custom-pki[Configuring a custom PKI].
21+
+
2022
[IMPORTANT]
2123
====
2224
Use 2048-bit certificates. The installation fails if you use 4096-bit certificates with Prism Central 2022.x.

0 commit comments

Comments
 (0)