Forum Discussion
jnantel
Nimbostratus
Apr 13, 2012SSL CRL import
I have a file in PEM format converted from a microsoft DER format. There is just one thing that every single piece documentation assumes: That everyone knows how to get get it into the loadbalancer and reference in the client SSL profile.
I do not know how to do this. Would someone care to explain? I figured adding it in the certificate section would be the way to go. NOPE, I get "Key Mismatch" and it fizzles.
Jonathan
17 Replies
- nitass
Employee
I figured adding it in the certificate section would be the way to go. NOPE, I get "Key Mismatch" and it fizzles.you may have to verify whether certificate and private key matches. if so, importing them to ssl certificate section, set them in clientssl profile and finally assign it to virtual server. - hoolio
Cirrostratus
Are you trying to import a CRL file or a cert and key? A CRL file doesn't have a private key. If you meant a cert and key, Nitass's link should help. - nitass
Employee
oops, thanks Aaron. i just noticed CRL in the title. :D - jnantel
Nimbostratus
I think this may b ea winner! I'll let you know how it works out. - What_Lies_Bene1
Cirrostratus
How would you upload a CRL file if the device is in Appliance Mode? - BT_90520
Nimbostratus
has to go through tmsh then or configuration utility since the restriction is as below (and no bash). - What_Lies_Bene1
Cirrostratus
Thanks BT but there's no option in the GUI and the solution in the link assumes the file is on the box already. My problem is how to get the file on the box in the first place. - BT_90520
Nimbostratus
I dont have a box with appliance box but saw SOL stating possible but from the "System ›› Device Certificates : Device Certificate ›› Device Certificate" - What_Lies_Bene1
Cirrostratus
Thanks BT but that won't work for importing a CRL. I wonder if this can be done via the serial console or if even that would force me into tmsh. No way of checking myself. - What_Lies_Bene1
Cirrostratus
You can still login as admin using the serial console, it's worth a try I'd say.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects