Forum Discussion
smp_86112
Cirrostratus
Apr 07, 2010Changing LTM Device Certificate from 1024 -> 2048 key
I need to update the Device Certificate on an LTM v10.1.0 from 1024 to 2048. The doc says "Available key lengths are 512, 1024, or 2048 bytes." However none of those options are available to select during the renewal process. How do you convert a 1024 Device Certificate to 2048 bit encryption?
Also just a heads-up to anyone running a vulnerability scan. This month our scanner suddenly reported 1024 bit SSL keys as a vulnerability.
- nathe
Cirrocumulus
Hi smp, - smp_86112
Cirrostratus
Yes, when creating a *new* certificate you can select 2048 bits. But I needed to convert an existing certificate. I did some testing yesterday on this. I simply created a new cert with the dialog box you presented, then renamed the cert and key file to server.crt and server.key, moved them to the right spot on the filesystem and restarted httpd. That seemed to do the trick. - hoolio
Cirrostratus
Thanks for clarifying. If you're using that cert with GTM, you might still need to sync the cert as the public key would have changed (just a guess though). - smp_86112
Cirrostratus
Yes, you are exactly correct. I need to run
on the unit with the new Device Certificate, which add the new cert to the Trusted Device Certificates list on the GTM.bigip_add
- Hamish
Cirrocumulus
Posted By smp on 04/08/2010 05:25 AM
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects