Forum Discussion
Is ca-bundle.crt updated when I update BIG-IP ?
I compared ca-bundle.crt on BIG-IP between 11.5.x and 12.1.x. Cause of a problem of client certification auth I faced.
What I found difference is that is following:
BIG-IP 12.1.x (VE) :
- 7108135 2017-04-29 20:18 /config/ssl/ssl.crt/ca-bundle.crt
BIG-IP 11.5.x (appliance):
- 3635692 Jan 16 2016 /config/ssl/ssl.crt/ca-bundle.crt
When I update 11.5.x to 12.1.x , the ca-bundle.crt will be replaced newer one ? OR Should I copy the ca-bundle.crt from 12.1.x to 11.5.x?
I need correct GlobalSign Root CA, but a ca-bundle.crt on 11.5.x has duplicated CA inside ( same subject key they have ). Also number of GlobalSign CA on 12.1.x is 9. That is more than 3 on 11.5.x.
Thanks for reading.
- iaineNacreous
Hi
Yes, as part of an upgrade the ca-bundle gets updated. If you want to update without upgrading the OS then there is an iApp available to assist - https://f5.com/solutions/deployment-guides/ca-bundle-iapp-big-ip-v115-v12
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com