For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Brad_146558's avatar
Brad_146558
Icon for Nimbostratus rankNimbostratus
Apr 30, 2014

Updating UCC Certificate in a Production Environment

I don't have an environment where I can test this right now, but in our production environment we use UCC SSL certificates to support 100 websites. All of our virtual servers use the same profile, which references this 100 website UCC SSL cert. If I update this cert with a new one because we add website 101 to the UCC cert, do you believe this will cause an interruption to end users?

 

We plan on doing this off hours but I was just hoping someone might have had some experience with it and so I could give some expectations to end users.

 

1 Reply

  • In lieu of a better answer, or any answer, I'd say it depends on BIG-IP version and platform. In the early days, a config load like this may have taken several seconds and would have interrupted every affected VIP. As of v11 and newer platforms, the interruption is likely very minimal. Nonetheless, if a user is trying to perform an SSL handshake at the exact moment that the certificate configuration is changing, they would certainly experience a hiccup, and I'm not sure there's any way around that. I'd say it's always a best practice to do this sort of configuration change during maintenance periods.