Configuring Server Certificate
When you configure Veeam Service Provider Console Server certificate, you can specify what TLS certificate must be used. Veeam Service Provider Console offers the following options:
- Import an existing TLS certificate from the certificate store. This is the recommended option.
- Keep the default self-signed TLS certificate generated by Veeam Service Provider Console during installation or upgrade.
- Generate a new self-signed TLS certificate.
Importing Certificate from Certificate Store
- For a multi-domain certificate:
- The certificate subject is equal to the fully qualified domain name (FQDN) of the Veeam Service Provider Console server. For example: CN = vac.domain.local.
- The Subject Alternative Name field must contain the FQDN of the Veeam Service Provider Console server. For example: DNS:vac.domain.local. If you want the certificate to cover cloud gateways, the filed must also contain all cloud gateway FQDNs.
- For a wildcard certificate:
- The certificate subject is equal to the wildcard domain entry of the Veeam Service Provider Console server. For example: CN = *.domain.local.
- The Subject Alternative Name field must contain the wildcard domain entry of the Veeam Service Provider Console server. For example: DNS:*.domain.local. If you want the certificate to cover cloud gateways, the field must also contain the wildcard domain entries of cloud gateways. Otherwise, these cloud gateways will not be trusted. Management agents will not use them for communication with Veeam Service Provider Console server.
Note: |
It is recommended to use different TLS certificates for Veeam Cloud Connect and Veeam Service Provider Console server in distributed deployments. Using the same certificate on multiple machines may compromise the private key of the certificate. |
For details, see Accessing Veeam Service Provider Console.
- At the top right corner of the Veeam Service Provider Console window, click Configuration.
- In the configuration menu on the left, click Certificates.
- At the top of the list, click Install > Server.
- At the Certificate Type step of the Manage Certificate window, select the Select certificate from the certificate store option.
- At the Pick Certificate step, select a certificate that you want to install and click Next.
Note: |
Consider the following:
|
- Review the certificate settings and click Finish.
- Log on as Administrator to the machine where Veeam Service Provider Console Server component is installed.
- Restart the Veeam Management Portal service.
- Refresh the Veeam Service Provider Console portal page.
Generating New Self-Signed Certificate
Note: |
If you replace the default certificate with another self-signed certificate, you need to do the following:
|
To generate a new self-signed TLS certificate, do the following:
For details, see Accessing Veeam Service Provider Console.
- At the top right corner of the Veeam Service Provider Console window, click Configuration.
- In the configuration menu on the left, click Certificates.
- At the top of the list, click Install > Server.
- At the Certificate Type step of the Manage Certificate window, select the Generate new certificate option.
- At the Generate Certificate step, specify a friendly name for a certificate that you want to install and click Next.
- Review the certificate settings and click Finish.
- Log on as Administrator to the machine where Veeam Service Provider Console Server component is installed.
- Restart Veeam Management Portal service.
- Refresh the Veeam Service Provider Console portal page.
Related Topics

