Forum Discussion
wallst32_178793
Nimbostratus
Jan 06, 2016SSL profile client configuration
I installed a new SSL certificate on an F5 LTM, and created a new SSL client profile for it via the web GUI. I decided to use TMSH (ltm profile client-ssl profile-name) to compare the configuration ...
wallst32_178793
Nimbostratus
Jan 07, 2016We are running TMOS version 11.6. I believe the cert/keypair is selected correctly. The items were selected from the drop downs, and the ADD button was clicked which puts the entry in the GUI "box". Also, those should be the settings responsible for creating the "cert-key-chain" block shown in the config.
- Amine_KadimiJan 07, 2016
MVP
This is weird. What happens if you associate your created profile with a https VS and then open a browser to that VS and display the certificate from the browser, did you see the default F5 cert or yours? - wallst32_178793Jan 07, 2016
Nimbostratus
The correct certificate loads in a browser in both cases; when the SSL Profile contains the "chain" and when it does not. When the "chain" is not included, I used third party "SSL checkers" to confirm the chain validation. That is why I stated in my other comment I wasn't really sure if these additional settings are required. The chain bundle is already specified in the SSL profile (Client Authentication - Trusted Certificate Authorities).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects