Forum Discussion
senthil147_1421
Nimbostratus
Feb 17, 2018Device certificate replace in HA Sync group 13.x
Team
i need to replace self signed device certificate with CA signed certificate. But the devices are in HA group and running 13.1 version . If i renew the certificate will it break HA ? if ye...
Feb 17, 2018
Hello,
The device certificate is independent of the trust certificates used for the DSC configuration. You should be fine to replace it at any time.
One scenario that you need to be concerned about the device certificate is if you're using BIG-IP DNS (GTM), which uses that certificate as part of the trust for the iQuery protocol. If you switch to a CA signed cert then you should install the CA cert in the BIG-IP DNS Trusted Server Certificates list.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects