Forum Discussion
SAN SSL Certificate
I'm trying to generate a CSR for my exchange 2013 deployment with two Subject Alternative Names on it (both asterisk SAN's) one for .com and one for .net since we have both. When I input in the SAN field "DNS:.contoso.com DNS:.contoso.net" it accepts it correctly and generates the CSR, however when I send that to the CA, and it hands me back a certificate, it is missing the field all together.
I found an article saying it was a known issue that has since been resolved in 11.3, but just yesterday, we upgraded to 11.4.1 and I am still noticing the issue. Any help would be appreciated since F5 is fairly new in our organization and I am unsure how to proceed.
6 Replies
- Dan_Clark_75371
Nimbostratus
Did you order a UCC cert? If you summit the SAN filled in on a stander cert the CA will remove it when generating the cert.
- mengler_136249
Nimbostratus
I guess I'm not 100% sure what you mean. I am generating the CSR on the F5 itself, and submitting the request to my local authority. This wont handle internet traffic, so we wont be purchasing a certificate from a public authority. We already have that through our TMG server.
Maybe I am just not selecting a certain field, or generating it incorrectly on my CA?
- Kevin_Stewart
Employee
I think what Dan is asking is if you're specifying with the CA that this is a SAN certificate? It could be that the CA is stripping the SAN information.
- mengler_136249
Nimbostratus
I suppose I have never been aware that is an option? Traditionally, I generate CSR's through exchange in which you apply SAN to the CSR and then just generate a certificate on the CA by using the web server template. There isn't an option anywhere to specify if it is a standard or UCC or anything like that.
- Dan_Clark_75371
Nimbostratus
If you were buying a cert from A public ca you would need to buy a ucc or multi domain cert.If it is your own ca it's a different story. If you already have the cert on your exchange server why not export it with the privte key and just import to the f5
- Pragathishakart
Nimbostratus
If the URL of the exchange is accessed from outside network, it needs trusted certificate. It can be achieved by creating SAN certificate. As you mentioned, it is accessed internally, it is better to export the private key from the existing exchange certificate and upload it to F5 box.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com