Forum Discussion

lipos_54863's avatar
lipos_54863
Icon for Nimbostratus rankNimbostratus
Oct 13, 2009

ca-bundle update

I have a problem with updating my SSL ca-bundle :/

 

I'm running LTM 9.4.6 and until today the default ca-bundle took care of all certs for SSL offloading, but I lately got a certificate by VeriSign - Class 3 Extended Validation SSL SGC CA.

 

I was under the impresion that ca-bundle should already posses ca cert but I got a 'chain broken' error.

 

 

As advised I'm adding two first: http://www.verisign.com/support/verisign-intermediate-ca/extended-validation-pro/index.html to ca-bundle by SSH by pasting it (SOL6118). I can see that ca-bundle is adding those certs to the ca-bundle by viewing using GUI, but I still get a message about broken chain every time I'm viewing HTTPS :/

 

 

I tried to deleting certs for ca-bundle, doing the same with HTTPS cert/key but nothing works.

 

Is there somthigng that I need to update to enable new ca-bundle content or F5s should pick it up on it own?

 

 

Any idea what can be wrong with it?

 

  • Solved:

     

     

    SOL6401: Configuring the BIG-IP to use an intermediate or chain certificate with a clientssl profile

     

    https://support.f5.com/kb/en-us/solutions/public/6000/400/sol6401.html

     

     

    SOL10167: Overview of the ClientSSL profile

     

    https://support.f5.com/kb/en-us/solutions/public/10000/100/sol10167.html