Forum Discussion
Big IP DNS Certificate issues
Hi
I am reasonably new to F5 and am looking for some help in relation to Big IP DNS. My predecessor had configured Big IP DNS with a trial license, then he left the company. The trial has long expired but my company have decided to move forwards with Big IP DNS I have licensed and allocated resources This re-instated the original configuration(created by my predecessor) Although all servers are in the down state Several months back I renewed the management certificates of all devices and thought this might be related So I ran bigip_add to add the new certificates to the Trusted Server Certificates but nothing had started working yet.
I see the following in the GTM logs
iqmgmt_ssl_connect: SSL error: error:14094413:SSL routines:SSL3_READ_BYTES:sslv3 alert unsupported certificate (336151571)
Reading around this the un-support certificates seems to indicate I am using the wrong type of certificate, mine had been created using the CA using the webserver template, like the following https://devcentral.f5.com/questions/can-san-certificates-be-used-for-device-certificates Can anyone advise me as to whether this is still the case as this is some time ago (2012) Many thanks
1 Reply
- sjy2018_365312
Nimbostratus
I have updated my certificates as suggested in the article that I have referenced. Everything is now working as expected
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com