5V0-43.21 · Question #69
How would an operator replace the default certificate used by the Avi GUI with a trusted certificate?
The correct answer is A. Generate a certificate of type Controller Certificate, then assign it to the management VS. Option A is correct because Avi requires a certificate specifically typed as Controller Certificate - this type is purpose-built for the management plane. Once created, it must be assigned to the management Virtual Service (VS), which is the VS that serves the Avi GUI; without…
Question
How would an operator replace the default certificate used by the Avi GUI with a trusted certificate?
Options
- AGenerate a certificate of type Controller Certificate, then assign it to the management VS.
- BGenerate a certificate of type Controller Certificate, then update the Access Settings under
- CAvi can auto-generate a trusted certificate from the GUI and use it for the GUI access.
- DThe default certificate used by the Avi GUI is already trusted.
How the community answered
(26 responses)- A81% (21)
- B4% (1)
- C12% (3)
- D4% (1)
Explanation
Option A is correct because Avi requires a certificate specifically typed as Controller Certificate - this type is purpose-built for the management plane. Once created, it must be assigned to the management Virtual Service (VS), which is the VS that serves the Avi GUI; without that assignment step, the certificate exists in inventory but is never used.
Option B is a near-miss distractor - "Access Settings" is a real location in Avi, but the authoritative path to apply a trusted cert to the GUI is through the management VS assignment, not just updating Access Settings. The answer is also visibly truncated, signaling an incomplete/incorrect workflow.
Option C is wrong because Avi has no built-in ACME/CA integration to auto-generate a trusted certificate. It can only generate self-signed certificates on its own, which browsers will still flag as untrusted.
Option D is wrong because the factory-default certificate is self-signed by Avi's own CA, which is not in any browser trust store - hence the browser warning on first login.
Memory tip: Think "type then target" - first pick the right type (Controller Certificate), then hit the right target (management VS). If either step is missing or mismatched, the trusted cert never takes effect.
Topics
Community Discussion
No community discussion yet for this question.