Forum Discussion
Exporting SSL Certificate to another BIG IP
- Nov 25, 2017
I have done the changes successfully, and it worked by simply uploading the signed cert with the key and the cert key chain from the signed authority side.
Thanks :)
Hi
Based on your explanation, it seems the certs are all self-signed and they are already associated with with virtual servers through client or server ssl profiles.
If that is the case, I would vote for recreating self-signed certs and key on the new box but use the same cert and key name so that you don't need to change anything from existing client or server ssl profile.
One catch would be to import certs and key first before you import client and server ssl profiles.
- RaghavendraSYOct 05, 2017Altostratus
You can export certificates and key from F5-A and import in F5-B. While importing please import both certificate and key separately. It works fine and we did same in our environment
- RaghavendraSYOct 05, 2017Altostratus
Import both certificate and key separately with same name.
- F5_324021Oct 05, 2017Cirrus
Hello ,
Thanks for your replies,
So no need to regenerate a CSR from the new box?
simply exporting the SSL traffic Cert and its key will work?without the CSR presented on the box?
- RaghavendraSYOct 05, 2017Altostratus
Yes. that is correct. Please let us know once you did the above changes
- F5_Digger_13600Oct 05, 2017Cirrus
Exporting certs and keys from an old box and importing them in a new box will work.
However I think, overall time to complete this task, building new certs and keys on the new box would be much faster. Use tmsh command line script like below.
!! Install Key and Cert
- F5_324021Oct 06, 2017Cirrus
Just want to clarify here that our traffic certifications are not self signed and they are signed by an authorized CA ,all what we did on the old box is generating a CSR and pushed to the CA after that we got the cert file and a key with the cert key chain of the CA itself.
So in that case is it correct that we can just export the cert and the keys with the cert key chain to the new box and the SSL traffic certification will work fine or should we repeat the same process that was done on the old box.
Thank you..
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com