Forum Discussion
Renewing SSL certificate for SSL offload - question regarding CSR creation
We are doing SSL Offload (encrypt to clients, plaintext to servers) using a cert that needs to be renewed. The server admin sent us the .crt and .key files that apparently he generated from the server. However, since the F5 is the one handling the SSL encryption (and not the server), shouldn't the CSR be generated from the F5? I am wondering if I can use the renewed cert as provided and continue to do SSL Offload. Thank you!
If you have both the key and the cert, it shouldn't matter that it was generated on the server itself. Just import them both and configure the Client SSL profile to apply to the VIP.
- AJ_01_135899Cirrostratus
If you have both the key and the cert, it shouldn't matter that it was generated on the server itself. Just import them both and configure the Client SSL profile to apply to the VIP.
- Carlos_Colon_24Nimbostratus
thank you!! let me give it a shot.
- Ashish_ChakravaNimbostratus
- Do it after hours
- Take backup before cert update as something goes down you can rollback.
- Upload the cert
- And call it on your SSL profile.
- Carlos_Colon_24Nimbostratus
Thank you, Ashish! I backed up the F5 configuration this morning. The customer wants it renewed asap so I may not be able to wait until after hours. I will try to wait until late in the day.
- The_YCirrus
Yes you can. It doesn't matter where the cert is generated. As long as the cert is good you can use it.
- Carlos_Colon_24Nimbostratus
One last thing, are there any concerns with updating the Client SSL Profile in the middle of the day as long as I can make sure that the cert is good beforehand?
- The_YCirrus
The one thing you need to be aware of is that once you replace the cert with the new one any currently established connection will have to be re-negotiated.
- AJ_01_135899Cirrostratus
Obviously the safe answer would be to wait until after hours.
That said, this would be a quick rollout and rollback. To make the rollout and rollback faster you could create a new Client SSL profile (assuming there's only one VIP using this Client SSL profile), and just apply the new profile to the VIP. Rollback would be reverting to the old profile.
Just for thoroughness' sake, are there any intermediate certificates in the existing Client SSL profile?
- Carlos_Colon_24Nimbostratus
Thank you, AJ! There are intermediate certs in the existing Client SSL profile. One weird thing is that the cert is from InCommon but the chain is from Thawte. Not sure why it was setup that way.
- Carlos_Colon_24Nimbostratus
Thanks again for your help, AJ! Your 'just for thoroughness' sake' comment allowed me to notice that there were duplicate Client SSL profiles and to ignore/delete the one that had the chain from Thawte!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com