CA Certs for Server with Multiple IPs

illllm

ADSM.ORG Member
Joined
Jan 9, 2018
Messages
153
Reaction score
2
Points
0
Hi All I have a confusing situation:

Production Client Backup IP is 10.220.x.x (All prod clients use this IP)
Test and Dev Client Backup IP is 10.222.x.x ( All test and dev servers backup using this IP)
TSM Management IP is 72.x.x.x ( connects to Ops Center and also DB backup)

All three IPs are configured on the TSM server and have their own firewall rules etc.

How do I create a certificate with ONE sanDNS name and 3 sanIP address?
Should i create a CA cert for each of the IPs ? then make one default? If so , which one?
If I use 72.x.x.x, db backup and Ops Center will work. Client backups dont work. If I use 10.220, other two wont work.
 
Hi,

If memory serves me right, -san_dns-name <name> and -san_ipaddr <address> can have multiple values.

-san_dns-name host1.domain.com,host2.domain.com -san_ipaddr 10.10.10.10,10.10.10.11

I have not verified this yet.

Second option is to use wildcard for certificate and use different hostnames

And third option is to manipulate local host file
 
second and thirds options are not allowed by our security team :(
 
Back
Top