Forum Discussion
Creating Client SSL Profile using Certs from a new CA
I've uploaded some new certs with their keys and created Client SSL profiles for them to put on some load balancing virtual servers.
These new certs were issued by a brand new CA.
The old SSL Profiles nothing in their chain - just cert & key issued by OldOrgName.
The new SSL Profiles don't work.
Where on the F5 do I tell the F5 about the new CA?
Or is it entirely up to the Client to know how trust the new Certs in the new Client SSL Profiles when they connect to the VS?
3 Replies
- MatthewJC
Nimbostratus
Thanks guys, I was so wrapped up in the "new CA" side of things, expecting trust issues or whatever that I failed to check the newly issued certs properly.....it was just a SAN that was left off them.
test using "curl -vk https://vip:port/....."
it will show details of ssl session setup
- Injeyan_Kostas
Cumulonimbus
when you say don't work you mean that you got a warning or not work at all?
Client needs to trust this CA.
does it?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com