Forum Discussion
How to update SSL Client Profile after importing the renewed certificate
I was just searching for a solution to this behavior, and this is one of the first links that came up...so I thought I would drop by and post the official Solution Article on this:
SOL13345: The BIG-IP system may incorrectly associate a newly- imported SSL certificate/key pair to other SSL profiles
http://support.f5.com/kb/en-us/solutions/public/13000/300/sol13345.html?sr=35294954
Workaround
For a BIG-IP system that has already encountered this issue, you can recover the BIG-IP system by reloading the configuration or updating the SSL profiles. To do so, perform any of the following procedures:
Reloading the configuration
Updating SSL profiles
Reloading the configurationImpact of workaround: Traffic processing is briefly interrupted while the configuration reloads.
Log in to the Traffic Management Shell (tmsh) by entering the following command:
tmsh
Note: If you are currently logged in to the tmsh shell, you can skip this step.
Reload the BIG-IP configuration by typing the following command:
load /sys config
Updating SSL profiles
Impact of Workaround: None.
Log in to the BIG-IP Configuration utility.
Navigate to Local Traffic > Profiles > SSL > Client or Server, depending on the affected SSL profiles.
Click the name of the affected SSL profile.
Click Update.
Repeat Steps 2 through 4 for the remaining affected SSL profiles.
FIXED IN
Type of Fix - Versions Fixed - Related Articles
Release - 11.2.0 - SOL2200: Most recent versions of F5 software
Hotfix - 11.1.0 HF2 - SOL9502: BIG-IP hotfix matrix
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com