Forum Discussion
F5 GTM iquery woes
have two stand-alone GTM devices in opposing DCs and struggling to get the sync-group up and running. is it OK to use the same wildcard certificate bound as a device certificate for the iquery communication channel?
I had this same problem with certs from an internal CA. I figured out I had to load the CA certs under Global Traffic/Servers/Trusted Server Certificates. Putting them under Systtem/Device Certificates/Trusted Device Certificates was not enough. This was with 11.2.1
- Cory_50405Noctilucent
Are you attempting to setup a sync-only device group, or a GTM sync group?
http://support.f5.com/kb/en-us/solutions/public/13000/700/sol13734.html
- Rabbit23_116296Nimbostratus
GTM sync group. We are trying the wildcard certificate key / trusted device cert but its not happy. That's why I wasn't sure if I need to use the F5 self signed certs and import the opposing cert in the other GTM appliance.
iqmgmt_ssl_connect: SSL error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed May 8 15:51:15 lhr4-lb-01 err gtmd[6453]: 011ae0fa:3: iqmgmt_ssl_connect: SSL error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed (336134278)
- Cory_50405Noctilucent
Any certificate should work so long as it isn't expired.
So did you copy the wildcard certificate to /config/httpd/conf/ssl.crt/server.crt and overwrite the self-signed, or how are you attempting to use the wildcard cert?
- Rabbit23_116296Nimbostratus
yeah that file on both servers is verified to be the same cert. it is looking at it in encoded form however without any chain or private key
- Cory_50405Noctilucent
And you've added the certificate to the trusted device certificate list in each of the appliances?
http://support.f5.com/kb/en-us/solutions/public/6000/300/sol6353.html
- Rabbit23_116296Nimbostratusyes sire
- Rabbit23_116296Nimbostratus
they keys match in /config/httpd/conf/ssl.key/server.key on both appliances so yes now i am a bit lost as to what the GTM daemon is trying to do every 10 minutes to log the SSL handshake error.
- Cory_50405Noctilucent
Was the sync group working with the default self-signed certificates prior to changing them?
Wondering if httpd or something else needs restarted...
- Rabbit23_116296Nimbostratus
no first time im trying to get the sync group working. following that article, tried self-signed and the wildcard cert that the appliance uses for XUI and also tried bigstart restart httpd with no joy..
- Cory_50405Noctilucent
And iqdump isn't going to be helpful since the certificates aren't validating.. Seems you've tried just about everything. Might be best to get a support case open.
- Rabbit23_116296NimbostratusThanks for the advice so far though.
- mimlo_61970Cumulonimbus
I had this same problem with certs from an internal CA. I figured out I had to load the CA certs under Global Traffic/Servers/Trusted Server Certificates. Putting them under Systtem/Device Certificates/Trusted Device Certificates was not enough. This was with 11.2.1
- Rabbit23_116296NimbostratusDid the Job! Thanks
- briceNimbostratusWanted to point out that all levels in the certificate chain will be required. We had to import the cert, intermediate, and the root that signed them.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com