jim goodman wrote:
I did hear back - Basically it is kinda backwards from what I think it should be
The SSO is a SMH hosting the VCA to SMH hosting the VCRM
The SMH hosting the VCRM needs to have the SMH Certificate of the SMH hosting the VCA
So for every VCA you want to have SSO to VCRM, you have to add the certificate of the SMH hosting the VCA
It is a manual process so if you have 3000 VCA's you want to have SSO with the VCRM you will need to install each certificate for each SMH hosting VCA one at a time.
Looks like, the correct way to collect all certs from VCAs is mentioned in HP SIM as a Repair action:
"Import Secure Sockets Layer (SSL) certificate of the managed system to HP SIM. This lets HP SIM trust the System Management Homepage of the managed system. To run this option SSH service should be running on target systems."
Although I'm not fond of installing OpenSSH everywhere.