Forum Discussion
Creating a new device certificate - signed by internal CA
I am using version 11.5.3. I have a requirement to update the device certificate with an internal CA signed certificate. We have a self signed cert that wont expire until 2025. I am planning on doing the following procedure
- Device certificate -> Renew -> finish - **Will this replace the existing cert already ?
- I am assuming it won't. So I will export the cert. This will generate a CSR.
- Once I get a signed cert, I will import it. How do I replace the self signed with this CA signed?
Please correct me if I am wrong.Thanks!
- amintej
Cirrus
Hello,
I modified a little bit your procedure:
-
System > Device certificate > Renew -> Please, be sure to select "Issuer: Certificate Authority". This action will generate CSR, copy csr text at the end of the wizard and send to your CA(issuer). Note CSR files have headers:
-----BEGIN CERTIFICATE REQUEST----- -----END CERTIFICATE REQUEST-----
-
Yes, you are right no action at this point.
-
Once you receive the certiticate, import the CA file
`System ›› Device Certificates : Trusted Device Certificates
Finally, import F5's certificate signed by your CA:
`System ›› Device Certificates : Device Certificate
and this will replace the certificate immediately if the verification is OK in F5.
-
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com