- Certificates used on the FlashArray must be PEM-formatted (Base64-encoded).
- Intermediary certificates are not supported for use with KMIP.
- Using the Purity internal management certificate for KMIP configuration is not supported.
Procedural guide to generate a FlashArray certificate and construct a CSR for mutual TLS trust with CryptoHub.
pureuser@purefa-ct0:# purecert create cert_1 --self-signed --common-name purefa
pureuser@purefa-ct0:# purecert construct cert_1 --certificate-signing-request