For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

jk303's avatar
jk303
Icon for Nimbostratus rankNimbostratus
Sep 06, 2018

BIG-IP DNS and LTM - Certificate Trust

Hey all,

 

Big-IP DNS - has signed device cert by private CA.

 

Big-IP LTM - has signed device cert by private CA.

 

Big-IP DNS - when configuring GSLB Servers and adding LTMs then running bigip_add on DNS box to form trust with the added LTMs - never turn GREEN. /var/log/gtm showing cert validation errors. When I look at the Trusted Cert - I see that each box has each others cert inside trusted certificate.

 

The fix seems to be - when I add the entire chain in device certificates on DNS device (not just the cert) but the device cert / intermediate cert / ca certs all together - I can then get connection and GREEN status between the DNS and LTMs.

 

BUT - now I see the CA cert as part of the trusted certs inside both LTM and also inside DNS boxes. Wouldn't that be possible TRUST issue that anyone with a CA cert would be trusted?

 

Running 13.x code - any good documentation that covers this and validation IF I need entire chain would be helpful.

 

Thanks for feedback!