For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Kittipong's avatar
Kittipong
Icon for Nimbostratus rankNimbostratus
Sep 30, 2016

Why F5 don't show the expired certificate in ca-bundle

I run command "tmsh run sys crypto check-cert" on my test F5 but it don't show the expired certificate in ca-bundle. F5 still show other expired certificate. In the ca-bundle have the expired certificate that I check via GUI.

 

But I run same command on other F5, it show all the expired certificate include the expired certificate in ca-bundle.

 

Why the F5 didn't show the expired certificate in ca-bundle?

 

Thank you

 

2 Replies

  • Bundle certificate is combined of multiple certificates & it only display live certificate validity. Though GUI you can see certificate in Drop down list & it will show expiry date.

     

    LTM log will show the expire certificate details. Please correct me.

     

  • tmsh run sys crypto check-cert --Only checks the FIPS module. Your CA bundle is not "saved" on your FIPS module. Therefore, you have to use the GUI to check the bundle, by clicking on it and reviewing what it contains.; also since it is not an individual cert, the GUI will not show which Certs in the bundle are expired, since a bundle is a layered cert list.