Client-managed TLS
Quick start

OneView documentation

Client-managed TLS

Use certificates managed by the client.

When to use it

Use client-managed TLS when the organisation already owns certificate issuance and renewal and wants OneView to terminate HTTPS.

The certificate must match the configured hostname. Select Client-managed TLS in the installer and provide the certificate and private key through the supported protected input. Provide the certificate chain when the organisation's certificate packaging requires it.

Responsibilities

The client must:

  • Renew the certificate before expiry.
  • Protect the private key.
  • Supply the certificate through the supported installer or network-change workflow.
  • Apply the documented network-change workflow after approved certificate replacement.

Never copy the TLS private key into the database, an application form, or a support request.