Forum Discussion
SSL offloading
Hi All,
Can you please let me know what is ssl intermediate certificate in f5 ? How to identify this in SSL certificates list. today I come across and issue that I have renewed one SSL certificate and it did not worked . due to intermediate certificate not renewed.
how to know if the certificate that taged under VIP is associated with intermediate certificate ? because last week i renewed another cert for other vip it worked just with out any issue.but today the cert i renewed for the vip gave problem .
2 Replies
- Michael_Jenkins
Cirrostratus
Not sure if this is the same issue you're having, but we recently had an issue after renewing certificates where some users were getting invalid certificate messages, and it was because we did not have the bundle associated to the clientssl profile. When creating the profiles, we needed to add the cert, key and bundle because (we were using GoDaddy) they changed their certificate authority chain to include other certs that the users didn't have. So you may need to update the bundle on the f5 as well.
SOL3302 talks about using SSL chains.
Hopefully this at least helps you in your journey to find the answer.
- StephanManthey
Nacreous
Hi vvskaladhar,
the intermediate CA bundle will be provided by your certificate authority.
In case you are configuring an intermediate CA (has to be imported as certificate (bundle) to TMOS filestore as well) in a client-ssl profile, the intermediate CA certificate will provided along with your server certificate to the client during initial SSL handshake.
Based on the intermediate certificate the client is able to validate the chain of trust to one of the root CAs which are trusted by the browser.
Your server certificate has an information about the issuer (signing CA). This string has to match exactly the common name in the end of chain certificate of your intermediate CA bundle.
If these names do not match, the client can not verify the chain of trust.
With shifting to SHA256 hashed certificates it is very likely your CA has a new signing entity deployed (verify the common names) and this is causing the mismatch.
Thanks, Stephan
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com