Accepting self-signed SSL certificates

You are prompted to accept security certificates the first time you connect to or monitor remote data movers.

Each data mover installation runs on a web service that creates and maintains a self-signed Secure Sockets Layer (SSL) certificate. The certificate secures interactions with the data mover, such as establishing connection, monitoring or upgrading. When the IBM Data Protection for VMware vSphere plug-in initiates communication with each remote data mover, you are prompted to accept a security certificate. After the certificate is accepted, that information is retained for future communications with the same remote data mover. You are presented with the details of the certificate the first time a connection is established. You can accept or reject the certificate.

To help ensure the security of the connection, you can compare the contents of the self-signed certificate presented in a browser by IBM Data Protection for VMware in the vSphere plug-in with the equivalent certificate on the installed web server. To do this, set up a keytool to access the keystore. For instructions, see Verifying a Data Protection for VMware self-signed web server certificate.

If you accept the self-signed certificate, subsequent connections between the host and data mover are digitally signed and will not be challenged. If the local file is deleted, a challenge to accept a new digital certificate will be issued on the next operation.

If you reject the self-signed certificate, the connection is refused.