Skip to main content
Perform the following steps in the CryptoHub web UI.

Sign the FlashArray CSR with a CryptoHub CA created during Endpoint deployment

1
Go to the PKI and CA > Certificate Management menu.
2
Expand the Client App TLS CA until you see the Pure Storage FlashArray certificate.
3
Right-click the CryptoHub CA certificate that issued the Pure Storage FlashArray certificate and select Add Certificate > From Request.
4
In the Subject DN tab, set the Common Name to the Application Name you noted above.
5
Leave set all default values in the Basic Info tab.
6
In the V3 Extensions tab, select the TLS Client Certificate Profile and select [ OK ].

Export the FlashArray and CA certificate

1
Right-click the FlashArray certificate you just issued and select Export > Certificate(s).
2
Change the Encoding to PEM and select [ Browse ].
3
Choose a filename for web transfer and select [ OK ].
4
Select [ OK ]. You should see a message stating the certificate was successfully written. Select [ OK ].
5
Download the PEM certificate file when prompted to by your browser.
6
Repeat steps 1-5 to export the CryptoHub CA certificate.
In the next section, we will configure the FlashArray certificate and CA certificate using the FlashArray CLI.