Forum Discussion
Akhilesh_128432
Nimbostratus
Mar 09, 2016Importing SSL certificate on F5
I have few questions regarding importing self signed certificate on F5 LB. I have generated a SSL certificate using keytool already and now am planning to use the same certificate in F5 for client SS...
Kash_118367
Nimbostratus
Mar 09, 2016You need to copy the certificate in text editor and save in txt format. Also, when you say "key tool" did you meant CA (Certificate Authority)? as you are trying to genereate self signed certificate you will not need certificate from CA.
You can refer solution article SOL14620 - https://support.f5.com/kb/en-us/solutions/public/14000/600/sol14620.html4
- Akhilesh_128432Mar 10, 2016
Nimbostratus
Key tool is a command in java to generate and import SSL certificate. My questions are not related to generating certificate. I had certificate and key already generated, which is a self signed certificate. My questions are more on the certificate and key format.my private key is in pkcs.8 format and I wondering will it support on F5 or any other standard format we need to convert before we upload to F5, (like pem format or pk12 format etc) - Kash_118367Mar 10, 2016
Nimbostratus
You can convert into pkcs 12; Importing a PKCS 12 (IIS) file PKCS 12 is a specifically formatted archive file that is used for storing cryptographic objects in a single file. The PKCS 12 file has an extension of .PFX and is compatible with Windows IIS. To import a PKCS 12 file, perform the following steps: Note: The BIG-IP system automatically converts PKCS 12 certificates to PEM format when the files are imported. Impact of procedure: Performing the following procedures should not have a negative impact on your system. Log in to the Configuration utility. Navigate to System > File Management > SSL Certificates List. Click Import. From the Import Type list, select PKCS 12 (IIS). In the Certificate Name section, type a name for the certificate. In the Certificate Source section, click Choose File. Click Import. - Akhilesh_128432Mar 10, 2016
Nimbostratus
agreed, how about the private key. currently my key is in pkcs8 format. Do I need convert that or directly I can import on F5 - Kash_118367Mar 14, 2016
Nimbostratus
Have you already tried to import pkcs8 directly? I would say covert pkcx8 format to text and then import to F5.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
