- Certificates used on the FlashArray must be PEM-formatted (Base64-encoded).
- Intermediary certificates are not supported for use with KMIP.
- Using the Purity internal management certificate for KMIP configuration is not supported.
Pure Storage FlashArray
Create a FlashArray certificate and construct a CSR
Procedural guide to generate a FlashArray certificate and construct a CSR for mutual TLS trust with CryptoHub.
Before enabling RDL on the FlashArray, the array and the CryptoHub must establish a mutual trust relationship by validating their respective digitally signed certificates.
Notes about certificates:

