Forum Discussion
Mic_108850
Altostratus
May 07, 2010HTTPS and SSL certificate for 2 BIG-IPs
Hi,
I have 2 BIG-IPs in differents locations (they are configured in Symetrical deployement mode)
BIG-IP 1:
VS_a1.test.domain.com (https)
with Pool (ip1:443) ip1...
Michael_Yates
Nimbostratus
May 10, 2010Mic,
I've done exactly what you are talking about across multipe F5 Pairs with Wildcard SSL Certificates and haven't had any problems in the past.
I can't say that I've ever had the problem that Hamish is describing, although you can never be too safe. We've thought of the Security aspects of having the SSL Certificates on the F5's and we actually use them as a storage repository for SSL Certificates that are created and not used on the F5's (so that we can keep track of them in case the server has a failure).
In the event of an F5 RMA (which in 4 years I've only had to do one, and that was an SSL Accelerator Card Failure) you can retrieve and then delete all of the current SSL Certicates that reside on an F5 to keep them secure in your companies hands.
They are located in the following directories:
/config/ssl/ssl.crl
/config/ssl/ssl.csr
/config/ssl/ssl.key
/config/ssl/ssl.crt
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
