Forum Discussion
OWA , which type of certificate is supported on F5 11.6?
Dears;
our customer provide me cerifcate.p7b , f5 do not allow to import it and i tried to copy and past as text also same problem ?
.crt and x509 is required ?
please advice
23 Replies
- nitass
Employee
you can convert p7b to pem format. anyway, p7b does not contain private key. ssl offloading requires private key.
- DC_Jordan_18536
Nimbostratus
They provide me .pfx also f5 is not accepted , they told me they have cert with key , so please can you advice
- nitass_89166
Noctilucent
you can convert p7b to pem format. anyway, p7b does not contain private key. ssl offloading requires private key.
- DC_Jordan_18536
Nimbostratus
They provide me .pfx also f5 is not accepted , they told me they have cert with key , so please can you advice
- DC_Jordan_18536
Nimbostratus
They provide me .pfx also f5 is not accepted , they told me they have cert with key , so please can you advice
- DC_Jordan_18536
Nimbostratus
Which type of certifcate is required for f5 ?
- Sec-Enabled_658
Cirrostratus
If they provided you with a PFX, you should be able to import that into the F5 through the GUI interface depending on what version of TMOS you are running. A PFX file (PKCS11) should contain cert and key, so it should work. You import this file under system-> file management or under Local Traffic -> ssl certificates. Possible values are Key, Certificate, PKCS 12 (IIS), and Archive.
- DC_Jordan_18536
Nimbostratus
I choose key and certificate , give me error i will try pcks today , this certificate will be use in ssl profile as client ssl , is that write , and after import it then go client ssl and create new owa and select this imported one what i shall do?!
- DC_Jordan_18536
Nimbostratus
I choose key and certificate , give me error i will try pcks today , this certificate will be use in ssl profile as client ssl , is that write , and after import it then go client ssl and create new owa and select this imported one what i shall do?!
- nitass
Employee
yes. you may check ssl profiles article here. SSL Profiles by JRahm and John Wagnon https://devcentral.f5.com/s/articles/ssl-profiles-part-1
- DC_Jordan_18536
Nimbostratus
I imported file as u mentioned , but from server side , shall owa admin remove certifcate from iis (( when add profile virtual severs owa site is mot working ))
- nitass
Employee
but from server side , shall owa admin remove certifcate from iis (( when add profile virtual severs owa site is mot working ))
you can choose whether you want ssl on server-side (between bigip and server).
if you want ssl, assign serverssl profile to virtual server (i.e. both clientssl and serverssl profiles). pool is listening on ssl port.
if you do not want ssl, use only clientssl profile (i.e. no serverssl profile). pool is listening on http port. - eng_mohamadawad
Nimbostratus
we want just clienet ssl , but when i used this ssl profile in Virtual server , HTTPS is not open , so please advice ? port 443 when i remove it every thing is working normally (https)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com