Forum Discussion
Kesha_50406
Altostratus
Aug 13, 2013F5 BIG-IP WebGUI intermediate certificate
I don't see how I can install an intermediate certificate for the F5 BIG IP management WebGUI. The device seems to be using the "Device Certificate" (under System > Device Certificates) for its manag...
Kesha_50406
Altostratus
Aug 14, 2013Yep, uncommenting SSLCertificateChainFile, putting the signing certificate to the location it specifies and then restarting httpd solves the issue. Agreed that this will probablhy not survive an upgrade.
[root@dbnintaccvp06:Active:Standalone] ~ grep SSLCertificateChainFile /etc/httpd/conf.d/ssl.conf
Point SSLCertificateChainFile at a file containing the
SSLCertificateChainFile /etc/pki/tls/certs/server-chain.crt
[root@dbnintaccvp06:Active:Standalone] openssl x509 \
-in /etc/pki/tls/certs/server-chain.crt \
-noout -text | grep 'X509v3 Basic' -A 1
X509v3 Basic Constraints: critical
CA:TRUEVerification now works fine:
$ echo '' | openssl s_client -connect dbnintaccvp06:443 -showcerts -CAfile ./ca-root.pem | egrep '(BEGIN|Verify)'
-----BEGIN CERTIFICATE-----
-----BEGIN CERTIFICATE-----
Verify return code: 0 (ok)F5 should really add an option to configure certificate chain for the management WebGUI. I'll try to get a feature request for this.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects