When to use it
Use client-managed TLS when the organisation already owns certificate issuance and renewal and wants OneView to terminate HTTPS.
The certificate must match the configured hostname. Select Client-managed TLS in the installer and provide the certificate and private key through the supported protected input. Provide the certificate chain when the organisation's certificate packaging requires it.
Responsibilities
The client must:
- Renew the certificate before expiry.
- Protect the private key.
- Supply the certificate through the supported installer or network-change workflow.
- Apply the documented network-change workflow after approved certificate replacement.
Never copy the TLS private key into the database, an application form, or a support request.