Sign the host certificate using ESKM

See Client Certificate Creation and generate a CSR in FlashArray CLI before you proceed with the steps below.

1. Copy the generated CSR from Pure Storage FlashArray CLI and submit it to ESKM for
signing by the ESKMLocalCA as a client certificate.

Screenshot 2025-09-03 141229-20250903-084229.png


Generated CSR in Pure Storage FlashArray CLI

  1. Go to ESKM Management Console > Security > Certificates & CAs > Local CAs.

Screenshot 2025-09-03 141638-20250903-104556.png


Local CA

  1. Select the created CA and click Sign Request.

Screenshot 2025-09-03 141713-20250903-084714.png


Sign Certificate Request

  1. Select the previously created CA certificate name from the Sign with Certificate Authority dropdown list.

  2. Select Client in the Certificate Purpose section.

  3. Copy the host certificate content to the Certificate Request box and click Sign Request.

Screenshot 2025-09-04 112440-20250904-055441.png

Signed Certificate Information

  1. Copy the signed certificate and paste it into the Pure Storage FlashArray CLI.

  2. Click ESKMLocalCA from Local CAs, copy the ESKMLocalCA certificate, and paste it into the Pure Storage FlashArray CLI.

Screenshot 2025-09-04 112440-20250904-055441.png

CA Certificate Information