Forum Discussion
hc_andy_35682
Nimbostratus
Mar 07, 2012Subject Alternative Name (SAN) Certificates
Hi All,
We're about to install a SAN certificate for a series of FQDN's on the F5.
I've followed F5's guide on how to generate the CSR for SAN certificates but not sure what happens when I need to add a new FQDN to the existing SAN certificate further down the track???
https://support.f5.com/kb/en-us/solutions/public/11000/400/sol11438.html
Example:
CSR generated with following FQDN's:
- https://abc.com
- https://123.abc.com
- https://456.abc.com
Several months later the client has a requirement to also add in another FQDN https://789.abc.com.
Do I have to re-generate the CSR again and get a new SAN certificate from the CA vendor to cover all four FQDN's now???
Thanks.
Andy
2 Replies
- hoolio
Cirrostratus
Hi Andy,
Yes, if the SAN list needs to change you need to generate a new CSR and get a new certificate. You could reuse the same private key or generate a new one with the new CSR.
Aaron - hc_andy_35682
Nimbostratus
Thanks Aaron. Good to know this information incase it arises in the future.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
