Forum Discussion
How to delete Orphan certs and keys
you can generate expired list of SSL certificate & delete manually or through script. will popup error if it is in used.
https://devcentral.f5.com/questions/find-unused-ssl-certificates
delete sys crypto key web.test.com.crt
delete /sys crypto key web.test.com.crt
- AnushDec 12, 2016
Nimbostratus
Thanks for your comment. I already have list of certs/keys. I believed that if I use "delete sys crypto key" command, it will delete certs/keys but not delete from conf. file.
is it not true?
Thanks
- AnushDec 12, 2016
Nimbostratus
I just tried on one of our test box and yes that is correct that if you use "delete crypto" command, bigip.conf file still showing you it's there but if you use by GUI, it will get deleted from .conf file too. my problem is, deleting around 1000 certs/keys using GUI is not convenient so trying to find command or any other way which can clean up .conf file too.
Thanks
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com