To include one or more SAN (Subject Alternative Name) in the CSR, use the following supplementary command options (highlighted in bold text, appended to the end of the command):
fmos pki gen-csr -K server.key server.csr -n host1.domain.com
In the example above, we are generating a CSR that will reference the Application Server's configured FQDN, as well as "host1.domain.com". For Load Balanced Application servers, they often share a VIP alias, which typically is configured as the public hostname on each AS server, and would be "host1.domain.com" in this use case.
You can take that server.csr to the FMOS DB to sign, or to a customer's CA signing authority.
Comments
0 comments
Please sign in to leave a comment.