Applicability
This topic applies only to OCP Enterprise Edition. OCP Community Edition does not support this feature.
To help you manage certificates, OCP provides certificate management capabilities for storing and managing certificate files. You can upload CA certificates, server certificates, and server certificate private keys to OCP. These three files are a set of certificate files, and all three files must have the pem suffix.
Prerequisites
You have logged in to the OCP console as the ADMIN or ORG_ADMIN role.
If you have enabled SSL encryption for links within the same cluster, make sure that the root certificate
ca.pemof OceanBase Database and OBProxy in the cluster are consistent.
Procedure
Log in to the OCP console.
In the left-side navigation pane, choose System Management > Certificate Management. The Certificate Management page automatically appears.
In the upper-right corner of the page, click Upload Certificate.
In the dialog box that appears, specify the following information.
ParameterDescriptionCertificate Name The certificate name must be unique. - The certificate name must start with a letter and end with a letter or a number.
- The certificate name must be 2 to 32 characters in length.
- Only underscores (_) are supported as special characters.
Upload Certificate You can upload a maximum of three pem files. Make sure that the certificate files are valid and comply with the usage specifications of OBProxy and OceanBase Database. The certificate files must contain the CA certificate, server certificate, and server certificate private key. Otherwise, SSL encryption for links may fail. Remarks Optional. Specify additional information about the certificate. Click Upload.
