Forum Discussion
SLChamberlin
Nimbostratus
Apr 24, 2014Open HTTPS connections during SSL cert overwrite
An CA SSL cert & key were imported for use in SSL offloading and are working. The CA cert is nearing the expiration data. The plan is to import and overwrite the old cert and key with a new cert an...
nitass
Employee
Apr 24, 2014if key is changed when renewing, i think you have to create new certificate and key names and then assign the new certificate and key to clientssl profile. the change could affect only new connection. the existing connection should use the old configuration.
sol13253: Configuration changes to local traffic objects do not affect existing connections
http://support.f5.com/kb/en-us/solutions/public/13000/200/sol13253.html
- omniplexApr 24, 2014
Nimbostratus
I've also found that depending on the version that if the cert and key are already loaded into memory, you need to do something to cause the files to be re-read. Either changing the profile to something else and then back or reloading the configuration. Depending on your setup, you could update the standby device if this is in an HA pair, and fail over to that device and then update the previous device.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects