Forum Discussion

Ahmadj_283318's avatar
Ahmadj_283318
Icon for Nimbostratus rankNimbostratus
Nov 18, 2017

private key and intermediate certificate

Hi I received the Root certificate and the intermediate certificate but when i try to create SSL profile it asks me about the key can anyone help, please?

 

  • hI,

     

    Please let me know from where you create CSR file? If you created CSR file from F5 key will be available already. if CSR is created from server etc.. then you need to ask key from respective teams.

     

    Hope this helps.

     

  • hI,

     

    Please let me know from where you create CSR file? If you created CSR file from F5 key will be available already. if CSR is created from server etc.. then you need to ask key from respective teams.

     

    Hope this helps.

     

  • You have to create a certificate chain using the intermediate certificates.

     

    Add your wildcard certificate, private key and chain in the ssl profile (client).

     

    Cheers,

     

    Kees

     

    • KeesvandenBos's avatar
      KeesvandenBos
      Icon for MVP rankMVP

      You have to use the key that has been generated when the csr was created.

       

      When you import the certificate (by clicking on the csr) the BIG-IP will combine them in the webgui.

       

    • Ahmadj_283318's avatar
      Ahmadj_283318
      Icon for Nimbostratus rankNimbostratus

      To create sslprofile I should have certificate,key and chain so I choosed the root and old private key then the intermediate they provided me with root certificate and the intermediate certificate without the private key so because of this i am using the old private key which exist on F5

       

    • KeesvandenBos's avatar
      KeesvandenBos
      Icon for MVP rankMVP

      You don't need the root certificate. Only the chain of intermediates without the root. You will never receive the private key of the root and intermediates and the private key of your certificate is created the moment you generated the csr for your wildcard certificate.

       

    • KeesvandenBos's avatar
      KeesvandenBos
      Icon for MVP rankMVP

      You have to use the key that has been generated when the csr was created.

       

      When you import the certificate (by clicking on the csr) the BIG-IP will combine them in the webgui.

       

    • Ahmadj_283318's avatar
      Ahmadj_283318
      Icon for Nimbostratus rankNimbostratus

      To create sslprofile I should have certificate,key and chain so I choosed the root and old private key then the intermediate they provided me with root certificate and the intermediate certificate without the private key so because of this i am using the old private key which exist on F5

       

    • KeesvandenBos's avatar
      KeesvandenBos
      Icon for MVP rankMVP

      You don't need the root certificate. Only the chain of intermediates without the root. You will never receive the private key of the root and intermediates and the private key of your certificate is created the moment you generated the csr for your wildcard certificate.