Forum Discussion
tatmotiv
Aug 26, 2015Cirrostratus
I guess your cert/key bundle is in pkcs12 format? I'd try uploading the bundle (I understood this part is already working) and then use the openssl command line tool on the bigIP to split the bundle into separate key and cert files in pem format. Proper command line for that would be
openssl pkcs12 -clcerts -nokeys -in bundle.p12 -out cert.crt
openssl pkcs12 -nocerts -nodes -in bundle.p12 -out cert.key
Attention: this will produce an unencrypted private key file.
You can try to automate this by executing openssl as an external command through REST, but this might rise some problems with password protected bundles.