Forum Discussion
Multiple SAN SSL certificates to a single VIP
Hello ALL, I'm working on SSL certificate installation task wherein for a sigle VIP I have to associate multiple SAN certificates and each SAN certifcate has multiple URLs.
for exmaple: VIP - 10.10.10.10 has SSL cert of SSL1 and SSL2 and SSL1 has SAN name of x.learn.com,y.learn.com and x.learn.com. And SSL 2 certificate has the SAN name of A.learn.com, B.learn.com and C.learn.com.
Could you please suggest how can I achive this?
For example if a user access x.learn.com or a.learn.com using the same VIP then it should be accessible.
Regards, Thiyagu
1 Reply
- youssef1
Cumulonimbus
Hi,
Did you check this post: https://devcentral.f5.com/questions/client-ssl-profiles-using-sni-not-able-to-use-the-subject-alternative-name
It explain how you can achieve your need.
Response from Kevin (F5): SNI doesn't really care about what's in the certificate, but rather what you've defined in the Server Name attribute of the client SSL profile. I haven't tried this, but thinking you could create a separate client SSL profile for each SAN name that isn't covered by the wildcard, using the same cert/key, and then apply all of those to the VIP.
Let me know if you need help
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
