Objective
The Nodegrid OS now supports self-signed Certificate Authorities. The primary role of a CA is to digitally sign (with the CA's private key), and publish, the public key that is bound to a given entity. Please note the use of the recent Web forwarder, the ‘Browser Forwarder’, requires the use of signed certificates.
Overview of the configuration steps
- Generate the CSR on the Nodegrid OS
- Import the certificate into the user's laptop.
We will be using the web browser Chrome in the example.
Configuration
- Initial state:
It confirms the absence of valid SSL certificates:
- Generate the CSR:
In Security :: Certificates, click on “Create CSR”:
Fill-in the fields ; in particular, select “Self-Sign certificate”, and fill-in the “Subject Alternative Names” with the chosen FQDN and IP address of the Nodegrid (separated by commas, no space). Finish by clicking on “Generate CSR”:
- Apply the web certificate on the Nodegrid appliance:
- Then, click on Finish. The web browser will reload, and you will have to re-authenticate on the Nodegrid. Make sure the newly created certificate has the mention ‘Webserver’ in the column “Used by”:
- On the browser:
- Click on the padlock icon and see the certificate.
- Export the certificate to your computer ('Base 64 ASCII')
- Then, import that certificate into the browser:
- Go to “Settings” -> “Confidentiality and Security” -> “Security”
- Then, to “Manage the certificates”:
- Then in “Manage Certificates”, go to: “Local certificates” -> “Installed by you”, and import the certificate.
- Close the browser.
Visualization
On the login page of the Nodegrid, you visualize the new icon:
In the certificate info, you can see the status, expiration date, and Subject Alternative Names: