Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Halaman ini menjelaskan cara menambahkan dan mengelola sertifikat pihak ketiga yang digunakan oleh
Layanan Backup dan DR.
Layanan Pencadangan dan DR dapat terhubung ke endpoint eksternal layanan
pihak ketiga hanya jika endpoint tersebut memiliki sertifikat yang valid yang dikeluarkan oleh
Certificate Authority (CA) Publik yang terkait dengannya. Jika endpoint tidak memiliki
sertifikat, Anda harus menambahkannya.
Sertifikat divalidasi melalui daftar pencabutan sertifikat (CRL)
atau Protokol Status Sertifikat Online (OCSP). Jika endpoint CRL atau OCSP
tidak dapat dijangkau, sertifikat akan diperlakukan sebagai valid dan peristiwa
akan dibuat. Anda dapat melacak peristiwa ini di halaman Pantau>Peristiwa.
Sebelum memulai
Izinkan koneksi keluar dari perangkat pencadangan/pemulihan ke endpoint OCSP
atau CRL sertifikat menggunakan Cloud NAT. Secara default,
Cloud NAT memiliki akses ke semua rentang IP primer dan sekunder dari semua
subnet di region jaringan Virtual Private Cloud (VPC). Untuk membatasi akses Cloud NAT hanya ke subnet tempat appliance di-deploy, lihat Menentukan rentang subnet untuk NAT.
Peran dan izin IAM
Izin berikut diperlukan untuk operasi sertifikat
pihak ketiga:
backupdr.managementServers.manageSystem dan backupdr.managementServers.viewSystem
untuk menambahkan atau menghapus sertifikat
backupdr.managementServers.viewSystem untuk melihat sertifikat
Menambahkan sertifikat
Anda dapat menambahkan sertifikat yang ditandatangani sendiri atau yang diterbitkan CA pribadi ke endpoint layanan
pihak ketiga menggunakan halaman Kelola>Sertifikat. Misalnya, jika vCenter menggunakan CA pribadi atau sertifikat yang ditandatangani sendiri, Anda perlu menambahkan sertifikat ke konsol pengelolaan.
Gunakan petunjuk berikut untuk menambahkan sertifikat pihak ketiga:
Klik Kelola>Sertifikat.
Klik Tambahkan Sertifikat.
Anda dapat menambahkan sertifikat dengan salah satu cara berikut:
Salin sertifikat dan tempel di kotak Certificate.
Klik Pilih File dan upload sertifikat.
Klik Upload.
Menghapus sertifikat
Gunakan petunjuk berikut untuk menghapus sertifikat:
Klik Kelola>Sertifikat.
Klik kanan sertifikat yang ingin dihapus, lalu pilih Hapus.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-11 UTC."],[[["\u003cp\u003eThis page provides instructions on how to add and manage third-party certificates for the Backup and DR Service.\u003c/p\u003e\n"],["\u003cp\u003eCertificates are validated through Certificate Revocation Lists (CRL) or Online Certificate Status Protocol (OCSP), and if these endpoints are unreachable, the certificate is still treated as valid.\u003c/p\u003e\n"],["\u003cp\u003eAdding a certificate requires either copying and pasting it into the designated box or uploading the certificate file through the \u003cstrong\u003eManage\u003c/strong\u003e > \u003cstrong\u003eCertificates\u003c/strong\u003e page.\u003c/p\u003e\n"],["\u003cp\u003eTo delete a certificate, you must right-click it on the \u003cstrong\u003eManage\u003c/strong\u003e > \u003cstrong\u003eCertificates\u003c/strong\u003e page and confirm the deletion.\u003c/p\u003e\n"],["\u003cp\u003eYou must allow an egress connection from the backup/recovery appliance to the OCSP or CRL endpoints using Cloud NAT for the certificate validation to take place.\u003c/p\u003e\n"]]],[],null,["# Third-party service certificate\n\nThis page explains how to add and manage third-party certificates used by the\nBackup and DR Service.\n\nBackup and DR Service can connect to the external endpoint of a third-party\nservice only if the endpoint has a valid certificate issued by a public\nPublic Certificate Authority (CA) associated to it. If the endpoint doesn't have a\ncertificate, you need to add one to it.\n\nA certificate is validated either through certificate revocation lists (CRL)\nor Online Certificate Status Protocol (OCSP). If the CRL or OCSP endpoints\nare not reachable, the certificate is treated as valid and an event is\ngenerated. You can track these events on the **Monitor** \\\u003e **Events** page.\n\nBefore you begin\n----------------\n\nAllow egress connection from the backup/recovery appliance to the OCSP\nor CRL endpoints of the certificate using [Cloud NAT](/nat/docs/set-up-manage-network-address-translation). By default,\nCloud NAT has access to all the primary and secondary IP ranges of all\nsubnets in the region of a Virtual Private Cloud (VPC) network. To limit Cloud NAT access to only the subnet where the appliance is deployed, see [Specify subnet ranges for NAT](/nat/docs/set-up-manage-network-address-translation#specify_subnet_ranges_for_nat).\n\nIAM roles and permissions\n-------------------------\n\nThe following permissions are required for third-party certificate\noperations:\n\n- `backupdr.managementServers.manageSystem` and `backupdr.managementServers.viewSystem` for adding or deleting certificates\n- `backupdr.managementServers.viewSystem` for viewing certificates\n\nAdd a certificate\n-----------------\n\nYou can add a private CA issued or self-signed certificate to a third-party\nservice endpoint using the **Manage** \\\u003e **Certificates** page. For example,\nif a vCenter is using a private CA or self-signed certificate, you need to add\nthe certificate to the management console.\n\nUse the following instructions to add a third-party certificate:\n\n1. Click **Manage** \\\u003e **Certificates**.\n2. Click **Add Certificate**.\n3. You can add the certificate in either ways:\n\n - Copy the certificate and paste it in the **Certificate** box.\n - Click **Choose File** and upload the certificate.\n4. Click **Upload**.\n\nDelete a certificate\n--------------------\n\nUse the following instructions to delete a certificate:\n\n1. Click **Manage** \\\u003e **Certificates**.\n2. Right-click the certificate that you want to remove and select **Delete**.\n3. Click **Delete** in the confirmation dialog.\n\nWhat's next\n-----------\n\n- [Add vCenter and ESX server hosts](/backup-disaster-recovery/docs/configuration/add-vcenter-host)\n- [Discover and protect VMware VMs](/backup-disaster-recovery/docs/configuration/discover-and-protect-vms)"]]