Forum Discussion
Multiple SAN SSL certificates to a single VIP
Hello ALL, I'm working on SSL certificate installation task wherein for a sigle VIP I have to associate multiple SAN certificates and each SAN certifcate has multiple URLs.
for exmaple: VIP - 10.10.10.10 has SSL cert of SSL1 and SSL2 and SSL1 has SAN name of x.learn.com,y.learn.com and x.learn.com. And SSL 2 certificate has the SAN name of A.learn.com, B.learn.com and C.learn.com.
Could you please suggest how can I achive this?
For example if a user access x.learn.com or a.learn.com using the same VIP then it should be accessible.
Regards, Thiyagu
- youssef1
Cumulonimbus
Hi,
Did you check this post: https://devcentral.f5.com/questions/client-ssl-profiles-using-sni-not-able-to-use-the-subject-alternative-name
It explain how you can achieve your need.
Response from Kevin (F5): SNI doesn't really care about what's in the certificate, but rather what you've defined in the Server Name attribute of the client SSL profile. I haven't tried this, but thinking you could create a separate client SSL profile for each SAN name that isn't covered by the wildcard, using the same cert/key, and then apply all of those to the VIP.
Let me know if you need help
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com