Forum Discussion
Replace BIG IP self signed device certificate with CA signed device certificate
Hi Guys,
We have LTM, DNS, Viprion Hosts and Guests in which running device certificates are self signed. We have to replace these all self signed device certificate with CA signed device certificate. We have already CA which can provide certificates after raising CSR. I'm looking for best practices to renew/replace with minimum service impacts. LTMs and communicating with DNS via iQuery as well.
Your valuable response is highly appreciated.
Thank You
Regards
Ajeet Gupta
1 Reply
- Grumpy_Cat
Cirrus
Hi Ajeet,
This article covers how to replace the default device cert with a CA signed cert:
https://support.f5.com/csp/article/K42531434#replace
Covers iQuery comms as well. It's the same process where you'll need to add the new cert into their trusted device cert either using the bigip_add script or manually importing via TMUI.
Make sure the new SSL cert is not a wildcard otherwise comms will fail.
Let me know if you need anything else.
Kind regards
Ben
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com