Encryption
The failover cluster does not require encrypted communication by default.
To enable encrypted communication between the management server and other servers, install the following certificates on all cluster nodes:
The public CA certificate
The SSL certificate for the failover cluster
The SSL certificate must include:
the cluster role address
You can also include the hostname or IP address of each node. This is optional and can simplify upgrades later on, but may increase exposure to unintended connections.