Forum Discussion
Impact of client.crt and server.crt expiration
My device is currently running on L4 A-S.
The client.crt and server.crt expire in 2027.05.
DTDI and DTCA expire in 2035.
1. If client.crt and server.crt expire, will it affect HA or config sync?
2. If I need to update, I'll do it via CLI. Will it affect HA and config sync? I'm wondering if I need to set up new redundancy or reboot, or anything like that.
This is a very sensitive service, so there may not be a maintenance window, so I wanted to notify you in advance.
2 Replies
- Kerry
Cirrus
all members in a cluster needs server certificates, and their CA/INT cert's also loaded. if the certs are not on all members the Sync will fail, no impacts on the VS's and traffic passing though it, If you are using GTM/DNS wideIP pools, then the certs also need updating in GTM so GTM and see all the thus expect to load each updated Certs 2-3 times on all F5's, Some devices certificates are no Synced in clusters
K16951115
Hiii JJ
If the certificate expire, dont have impact into the operation, but will prevent adding new devices into device trust.
Check the this article
https://my.f5.com/manage/s/article/K47052252
Best Regards
José Labra.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com