Forum Discussion

jnantel's avatar
jnantel
Icon for Nimbostratus rankNimbostratus
Apr 13, 2012

SSL CRL import

I have a file in PEM format converted from a microsoft DER format. There is just one thing that every single piece documentation assumes: That everyone knows how to get get it into the loadbalancer and reference in the client SSL profile.

 

 

I do not know how to do this. Would someone care to explain? I figured adding it in the certificate section would be the way to go. NOPE, I get "Key Mismatch" and it fizzles.

 

 

Jonathan

 

  • Thanks for sharing...think root is not admin :)

     

    In appliance mode, the root user cannot log in to the device by any means, including the serial console.

     

     

    Actually I am puzzled. When you clicked the "import" button, we should be able to state the certificate type and in this case, mentioned it as "Certificate Revocation List" and followed accordingly. It was mentioned applicable for 10.2.1 above.
  • Latest I can look at is 10.1 so I can't help with newer versions. Do you have this option in 10.2.1?
  • yap at least from SOL and in my 11 above VE :)

     

    http://support.f5.com/kb/en-us/solutions/public/13000/800/sol13823.html
  • That article doesn't mention CRLs so I'm not sure how that would help, it's specifically for BIG-IP device certificates???
  • I saw it in the VE and in the drop down list box but my VE is not in appliance mode ... too bad cannot attached capture :)
  • OK, so not available in the version you have an issue with I guess. Can you try the serial console?
  • dont have access to physical boxes though but those are in config GUI