Forum Discussion
Mic_108850
Altostratus
May 07, 2010HTTPS and SSL certificate for 2 BIG-IPs
Hi,
I have 2 BIG-IPs in differents locations (they are configured in Symetrical deployement mode)
BIG-IP 1:
VS_a1.test.domain.com (https)
with Pool (ip1:443)
ip1 uses an SSL certificate
for a1.test.domain.com i have a specific SSL certificate on BIG-IP1
BIG-IP 2:
VS_a2.test.domain.com (https)
with Pool (www.domain1.com:443)
for a2.test.domain.com i have a specific SSL certificate on BIG-IP2
If i activate multiconnect mode on BIG-IP1 and 2 i will have
https://wa1.a1.test.domain.com
https://wa2.a1.test.domain.com
on the other one:
https://wa1.a2.test.domain.com
https://wa2.a2.test.domain.com
what is the best solution to use SSL certificate with multiconnect? can i use the same wildcard certificate on both BIG-IP for each VS_a1.test.domain.com and VS_a2.test.domain.com
or is there a better solution?
Thanks
- Hamish
Cirrocumulus
For test domains you could just use self-signed certs... Cheaper (i.e. free). The only down side with using the same wildcard cert across multiple devices is having to keep the keys and certs sync'ed across multiple devices, and you don't want to share your CA signed certs across TOO many devices (The more it's shared, the less secure it'll be. Especially if you have to swap boxes out for repair etc and the HD is returned or swapped out etc. - Michael_Yates
Nimbostratus
Mic, - Hamish
Cirrocumulus
As far as I am aware there is no secure delete facility on the F5's... WHich means even if you do rm the files, they're still there... - hoolio
Cirrostratus
Assuming the unit still boots, I wonder if you could use a utility like DBAN to securely wipe the HDD before returning a defective unit for an RMA.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects