Forum Discussion
amoxi_100233
Nimbostratus
Dec 18, 2007Block Web Application when SSL cert expires
Hello,
Is there a way to check the expiry date for the SSL certificate installed on the F5 LTM? Can F5 stop forwarding to the pool members if the cert is expired?
Please advice. ...
hoolio
Cirrostratus
Dec 18, 2007In more recent LTM versions, a message is logged and an SNMP trap/email can be generated when a cert is going to expire within 30 days or has already expired. This is described in SOL7574
(Click here).
I'm not sure there is a way to get details on the cert the LTM is presenting to clients in an iRule. If there isn't, you might be able to write an iControl program which checks the the validity of each virtual server's SSL certificate and disables the VIP if it is expired.
But I would think/hope getting a 30 day notice the cert is about to expire would allow you to avoid the failure altogether.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
