Forum Discussion
CraigM_17826
Altocumulus
Sep 24, 2009Generating a 2048 length CSR
Hi everyone,
Just trying to generate a CSR for a GoDaddy cert and I am running into a small problem. GoDaddy require CSR keylengths between 2048 and 4096 and it appears that the Firepass is generating a 1024 key length and there doesn't appear to be an option to specify the CSR key length using the web interface. Is there anyway of specifying the CSR keylength or are we stuck with whatever key length it currently generates?
tia
Craig
14 Replies
- Mike_61719
Cirrus
What version are you on? - CraigM_17826
Altocumulus
The Firepass is a FirePass 1200 running 6.0.3 with all the current hot fixes and cumulative hotfixes applied.
Craig - Mike_Ho
Cirrus
There is a recent KB article on this...
https://support.f5.com/kb/en-us/solutions/public/10000/500/sol10540.html
Short answer - create your key and CSR with Openssl, get the cert, then import them onto the Firepass. - CraigM_17826
Altocumulus
Hi Michael,
many thanks. Boy, you sure are active across all the forums!
Regards,
Craig - Mike_Ho
Cirrus
I hope that through helping others I can learn more about the Firepass myself. I wish this forum was more active so we could have more discussions about all the various FP features. - CraigM_17826
Altocumulus
Hi Michael,
well I now have a 2048 Godaddy ssl cert now indtalled on the Firepass. Thanks for the pointer to the article. The only issue I had was that the cert must include a pass phrase or else the FP will not allow you install it, well at least not via the web interface, I'm sure it could be installed via the shell.
Craig - Pang_18289
Nimbostratus
Hello,
I am also trying to generate a 2048 bit CSR for enTrust for the Firepass and will appreciate if you can help to answer my question about using the OpenSSL to create the CSR. I am using the command line as the support page.
openssl req -new -nodes -days 365 -newkey rsa:2048 -keyout new.key -out newcert.csr
Is the challenge password being ask in OpenSSL the same as the password which we enter into the Encryption Password on the Firepass GUI? - Mike_Ho
Cirrus
No.
Since your command has "-nodes" then your key is not encrypted and thus has no passphrase.
The challenge password will not be used on the Firepass. - Mike_61719
Cirrus
Yes 2048 can be generated by the firepass in version 6.1.1 and above. Some folks use other software, personal preference really. - Flex_40625
Nimbostratus
Hi, thanks for the reply. I checked and my version is 6.0.3 ?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
