Forum Discussion
F5_324021
Oct 05, 2017Cirrus
Exporting SSL Certificate to another BIG IP
Hello,
We are upgrading our F5 boxes and we need to to move all the traffic SSL certificates to a new box.
The certificates that are on the old box was signed by a CA after generating a CSR...
- Nov 25, 2017
I have done the changes successfully, and it worked by simply uploading the signed cert with the key and the cert key chain from the signed authority side.
Thanks :)
F5_Digger_13600
Cirrus
Hi
Based on your explanation, it seems the certs are all self-signed and they are already associated with with virtual servers through client or server ssl profiles.
If that is the case, I would vote for recreating self-signed certs and key on the new box but use the same cert and key name so that you don't need to change anything from existing client or server ssl profile.
One catch would be to import certs and key first before you import client and server ssl profiles.
F5_324021
Oct 05, 2017Cirrus
Hello ,
Thanks for your replies,
So no need to regenerate a CSR from the new box?
simply exporting the SSL traffic Cert and its key will work?without the CSR presented on the box?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects