Forum Discussion
Michael_59762
Nimbostratus
Aug 16, 2010Add ssl intermediate cert from F5 LTM Web GUI?
Hi. I'm trying to add ssl certificate from the web GUI first.
I just import cert & key but it seems I can't import intermediate CA?
In some cases, you need your intermediate CA as well.
Is this something the web GUI don't have? Where and how I can import the intermediate CA?
Also I attached a screenshot.
As you can see the SSL Certificate tab is inside the Local Traffic tab.
I just wonder if that mean these settings are only for internal network?
Is that mean anyone outside go to https://test.miccheung.com on their browser they won't able to get anything?
Thanks.
- samstep
Cirrocumulus
What do you mean you cannot import intermediate CA? Are you getting any error messages? There are no restrictions in the WebGUI, you do it in the same place: LTM/SSL Certificates you should be able to import it without any problems. Then in order to USE IT you need to select it in your clientssl profile. Have a look at the LTM documentation - Configuration Guide for LTM - Michael_59762
Nimbostratus
Hi. Yes, I did the same procedure show from your link when import key and cert. - samstep
Cirrocumulus
"Keys do not match" is an error if you are trying to attach a private key to a wrong certificate. F5 LTM ties certificates with keys using the name,it looks to me you are trying to name your intermediate certificate on F5 box using the same name as your website certificate. When importing your intermediate CA cert call it differently.i.e. "RapidSSL_Intermediate_CA". - Michael_59762
Nimbostratus
Hi. I'm not sure what you mean. Because when I go to existing cert I created I go to import cert I can't edit/create name. - samstep
Cirrocumulus
Yes, you must first import your intermediate CA cert as a SEPARATE cert, which you have already done based on your screenshot. In order to link it with your main test.miccheung.com ssl cert and key you have to create a ClientSSL profile under Profiles->SSL->Client. It is all pretty easy and straightforward. Please read the F5 documentation - I have already posted a link in one of my posts above. - kevinf_50687
Nimbostratus
If you click on the SSL Client Profile, Select Advanced, then you can select the appropriate Intermediate CA certificate under Chain. Of course, the CA must already be imported into the active F5 appliance.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects