Forum Discussion
Kesha_50406
Altostratus
Aug 13, 2013F5 BIG-IP WebGUI intermediate certificate
I don't see how I can install an intermediate certificate for the F5 BIG IP management WebGUI. The device seems to be using the "Device Certificate" (under System > Device Certificates) for its manag...
Kesha_50406
Altostratus
Aug 13, 2013I just tried that, unfortunate it still doesn't work. Here's the PKCS12 file containing both certificates:
$ echo ''| openssl pkcs12 -in dbn-vp6.p12 | grep BEGIN
Enter Import Password:
MAC verified OK
-----BEGIN CERTIFICATE-----
-----BEGIN CERTIFICATE-----
Enter PEM pass phrase:
The device accepts the PKCS12 file no problem, the Device Certificate/General Propertis shows two entries now, one for the device certificate, the other one for the signing one. But if I connect to the management interface I still get only the device certificate as part of the TLS handshake:
$ echo '' | openssl s_client -connect dbnintaccvp06:443 -showcerts | grep BEGIN
-----BEGIN CERTIFICATE-----
For comparison this is what should happen if the correct certificate chain is presented:
$ echo '' | openssl s_client -connect www.google.com:443 -showcerts | grep BEGIN
-----BEGIN CERTIFICATE-----
-----BEGIN CERTIFICATE-----
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects