For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Domai's avatar
Domai
Icon for Altostratus rankAltostratus
Nov 17, 2017

010717e1:3: Client SSL profile cannot contain more than one set of same certificate/key type.

and you cannot associate more than one set of the same certificate/key pair type with the profile

 

https://support.f5.com/csp/article/K15062

 

What does the above mean exactly...The artical says you can associate multiple Secure Sockets Layer (SSL) certificate/key pair types with a single SSL profile.

 

I created a client profile - and am trying to add lets say cert1 - key1, cert2 - key2 and I get the error. Am I missing something here?

 

Thanks Guys.

 

1 Reply

  • Kevin_K_51432's avatar
    Kevin_K_51432
    Historic F5 Account

    Greetings Domai,

     

    Would this sentence make more sense?

     

    "Starting in BIG-IP 11.5.0, you can associate multiple Secure Sockets Layer (SSL) certificate/key pairs of different algorithm types with a single SSL profile."

     

    I can't think of an instance where you would want multiple of the same in a single profile and believe this change came about as ECC doesn't have a native key exchange, so must use additional RSA (two types in one profile).

     

    Hope this is helpful!

     

    Kevin