Dell EMC Isilon 換憑證筆記

先把憑證輸入到 isilon 的設備中

# vi /ifs/local/server.crt
# vi /ifs/local/server.key

匯入憑證

# isi certificate server import /ifs/local/server.crt /ifs/local/server.key

檢查憑證是否有正確匯入

# cat /usr/local/apache2/conf/ssl.crt/server.crt
# cat cat /usr/local/apache2/conf/ssl.key/server.key

將複製憑證到每個節點

# isi_for_array -s ‘cp /ifs/local/server.key /usr/local/apache2/conf/ssl.key/server.key’
# isi_for_array -s ‘cp /ifs/local/server.crt /usr/local/apache2/conf/ssl.crt/server.crt’

停止網頁服務

# isi services -a isi_webui disable

列表出目前所有的憑證

# isi certificate server list -v

變更新安裝的憑證為預設

# isi certificate settings modify  –default-https-certificate=xxxxxxxxxxxxxxx

移除舊有的憑證

# isi certificate server delete yyyyyyyyyyyyyyyy

繼續提供網頁服務

# isi services -a isi_webui enable

驗證憑證是否正確安裝

# echo QUIT | openssl s_client -connect localhost:8080