nerdexam
Broadcom-VMware

5V0-23.20 · Question #60

How can a vSphere administrator replace the Supervisor Cluster API endpoint certificate?

The correct answer is B. Use the vSphere Client to replace the Workload platform MTG certificate. As a vSphere administrator, you can replace the certificate for the virtual IP address (VIP) to securely connect to the Supervisor Cluster API endpoint with a certificate signed by a CA that your hosts already trust. The certificate authenticates the Kubernetes control plane to…

Operating and Administering vSphere with Tanzu

Question

How can a vSphere administrator replace the Supervisor Cluster API endpoint certificate?

Exhibit

5V0-23.20 question #60 exhibit

Options

  • AUse the certificate-manager CLI utility to replace the Supervisor Cluster API endpoint certificate.
  • BUse the vSphere Client to replace the Workload platform MTG certificate.
  • CUse the vSphere Client to replace the NSX Load Balancer certificate.
  • DUse kubectl to replace the Supervisor Cluster API endpoint certificate.

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    72% (26)
  • C
    14% (5)
  • D
    8% (3)

Explanation

As a vSphere administrator, you can replace the certificate for the virtual IP address (VIP) to securely connect to the Supervisor Cluster API endpoint with a certificate signed by a CA that your hosts already trust. The certificate authenticates the Kubernetes control plane to DevOps engineers, both during login and subsequent interactions with the Supervisor Cluster. Verify that you have access to a CA that can sign CSRs. For DevOps engineers, the CA must be installed on their system as a trusted root. In the vSphere Client, navigate to the Supervisor Cluster. Click Configure then under Namespaces select Certificates. In the Workload platform MTG pane, select Actions > Generate Provide the details for the certificate. Once the CSR is generated, click Copy. Sign the certificate with a CA. From the Workload platform MTG pane, select Actions > Replace Certificate. Upload the signed certificate file and click Replace Certificate. Validate the certificate on the IP address of the Kubernetes control plane.

Topics

#Supervisor Cluster#API endpoint certificate#certificate management#vSphere Client

Community Discussion

No community discussion yet for this question.

Full 5V0-23.20 Practice