Sign each per-node CSR from Nutanix using the CryptoHub Certificate Authority. Export the signed certificates and the CA certificate — you will upload all of these to Prism Element in the next step.Documentation Index
Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
Use this file to discover all available pages before exploring further.
Sign a node CSR
Repeat the following steps for each CSR file downloaded from Prism Element.Right-click the CA certificate under the Generic KMIP service and select Add Certificate > From Request.
csrs.zip archive. Each CVM node requires a separately signed certificate.
Export signed node certificates
Export each signed certificate individually in PEM format.Click [ Browse ], enter a filename that identifies the node (for example,
node1-signed.pem), and click [ OK ].Export the CA certificate
Export the CA certificate that signed the node certificates. Nutanix uses this certificate to validate the CryptoHub’s identity during the mTLS handshake.
After completing these steps, you should have the following files ready for upload to Nutanix:
- One signed
.pemcertificate per CVM node - One
cacert.pemCA certificate
If you deployed a client endpoint in the previous step, the KMIP server root CA certificate (
Futurex Test Root CA (ECC).cer or Futurex Test Root SSL CA.cer) is already included in the endpoint zip. You can use either that file or the cacert.pem exported here when configuring the Certificate Authority in Prism Element.
