Forum Discussion
Nik_67256
Nimbostratus
Apr 06, 2012Updating Expired WebSite Certficates
Hi All/Aaron,
I wanted to update the websites that have expired certificates with their new certs in the ASM.
Which is the screen in asm that addresses this.
This screen should be able to
1) it gives us a view of which websites have their certs expired
2) and allows us to update the expired certs of these websites.
I tried checking all the documentations but was unable to locate it.
regards
Nik
3 Replies
- nitass
Employee
isn't it SSL certificate in LTM?
sol7574: Monitoring SSL certificate expiration on the BIG-IP system
http://support.f5.com/kb/en-us/solutions/public/7000/500/sol7574.html
Renewing an SSL certificate
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm_configuration_guide_10_1/ltm_ssl_certif_config.html
sol7573: Renewing a Certificate Authorities signed certificate that requires a new key without overwriting the current key and certificate
http://support.f5.com/kb/en-us/solutions/public/7000/500/sol7573.html
sol10561: The BIG-IP system may not use a renewed SSL certificate
http://support.f5.com/kb/en-us/solutions/public/10000/500/sol10561.html - Nik_67256
Nimbostratus
Thanks for responding.
Clarifying what exactly i wanted below....
If you goto local traffic-->SSL certficates , you will get a list of current certficates and their status. Here, i see few websites listed with expired certficates as well.
Wanted to know whats the significance of this. Is it that after re-newing the certficates of the websites through the webserver , we need to import those certficates here so that ASM treats these sites as legitimate? (Thought once the certs are renewed through the webserver it was enough)
regards
Nik - nitass
Employee
Is it that after re-newing the certficates of the websites through the webserver , we need to import those certficates here so that ASM treats these sites as legitimate?if bigip does SSL offloading, yes you have to import renewed certificate and private key (if private key is changed) to bigip. actually, it can also be done the opposite way - renewing certificate on bigip and then copying certificate and private key (if changed) to web server.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects