Forum Discussion
Auto renewal of device certificate
Hello everyone,
We have a customer who has two f5 machines in HA pair. And for them we have device trust based on default device certificates. After this trust was established we import new certificate, generated from our customer's CA, and they expired after two years.
We want to automate the process of renewal of certificates after their expiration. After research we see only how to accomplish this manually.
Do you have any ideas?
Thanks in advance.
Regards,
Preslav
Hi all,
I found the explanation. There's no option to renew device certificate automatically. And one correction - the device certificate is not used to establish trust relationship between HA units. In order to establish secure channel between HA peers we use /config/ssl/ssl.crt/dtdi.crt and /config/ssl/ssl.crt/dtca.crt certificates.
Device certificate (System -> Device certificates -> Device certificate) does not affect DSC (HA) synchronization. It does, however, affect DNS synchronization and iQuery communication.
More on BIG-IP certificates can be found here: https://support.f5.com/csp/article/K15664
Regards,
Preslav
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com