Enable trusted communication with external entities
Resiliency Platform interfaces with external entities for discovery and orchestration. It is typically done using APIs involving SSL/TLS communication using certificates presented by the external systems to provide a trusted and secure channel.
If the certificates are issued by a well-known public Certificate Authority (CA), Resiliency Platform can automatically establish a verified and trusted channel. However, if the certificates are self-signed or issued by a private CA, Resiliency Platform will not be able to automatically trust the certificates presented by the external systems.
In order to simplify this, it is required to provide self-signed or private CA certificate to Resiliency Platform. From version 3.6, following are the external entities for which self-signed or certificates issued by private CA need to install:
See About root CA certificates of NetBackup primary server and NetBackup Cloud Recovery Server.
See About root CA certificates of vCenter server .
See About root CA certificates of vCloud Director.
See About root CA certificates of NetApp enclosure.
See About root CA certificates of Azure Stack.
Resiliency Platform can be informed to trust the certificate presented by external systems without any verification. However, it is strongly discouraged to toggle off this button from a security standpoint. To access this feature, navigate to Settings > Miscellaneous > Peer Host Identity Verification settings.
Note:
The Peer Host Identity Verification settings is not honoured in Azure Stack configuration. So in case of Azure Stack configurations, the secure communication is always enable.