Forum Discussion
Fawad_29089
Apr 17, 2012Nimbostratus
Exchange Certificates on LTM
Hi,
I need some information for the installation of Public SSL certificates on F5 for Exchange. We will be using Single Virtual IP Address for all Exchange Services. So the certificate type I am thinking of using is Subject Alternate Name Certificate (SAN) – single certificate. I will generate one request each from the two LTM devices.
This is the document I am referring to for creating of Certificate Request. http://support.f5.com/kb/en-us/solutions/public/11000/400/sol11438.html .
We are doing SSL offloading on Exchange so all client SSL requests will terminate on F5 – which is pretty much the standard procedure.
•Do we need to generate certificate request on Exchange Servers as well?
•Is there any requirement to import Exchange Servers Certificates on F5 for each service?
After reading some documents and online forums I got this indication that the only device that requires certificate is F5 if you are doing SSL offloading. Let me know if this correct! How is your implementation for certificates?
Thanks,
Fawad Alam
- nitassEmployeeDo we need to generate certificate request on Exchange Servers as well?no, one certificate/key is enough.
- Fawad_29089Nimbostratus
Thanks for the reply!
Is this correct?
- nitassEmployeeSo it means that the only place where I need certificate is F5 and there is no need to generate certificate request from Exchange actually, you can create CSR on either bigip or exchange server. after getting certificate from CA, you are able to use it anywhere e.g. bigip, exchange server, etc.
- Fawad_29089NimbostratusI have few more questions regarding certificates:
- nitassEmployee1. Is device certificate has anything to do with the SSL certificate for Exchange?no
- John_Matlock_42NimbostratusHi Fawad,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects