# F5 Big-IP Trust Internal CA Chain certificates for Web Servers

**URL:** <https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504>\
**Category:** Technical Forums\
**Created:** [September 4, 2025, 6:11pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504 "2025-09-04T18:11:34Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![pcourtois](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/pcourtois/32/23197_2.png) [@pcourtois](https://community.f5.com/u/pcourtois)\
**Post date:** [September 4, 2025, 6:11pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504/1 "2025-09-04T18:11:34Z")

</div>

Great day F5 Friends,

Currently, we use a wildcard certificate on all of our web servers which requires us to replace it when the certificate is expired. The Big-IP isn’t configured to “only” trust this certificate on these servers which is less secure.

Where I would like assistance in is how to configure my Big-IP’s to trust only our internal CA for those pools.&nbsp; \*NOTE: &nbsp;I will configure GPO to auto-enroll the web servers for SSL certs and bind to IIS.

Is it as simple as uploading the Chain cert to the Big-IP and then create a server ssl profile pointing to that Chain cert and adding the profile to the VS?

Thanks for your time and energy in this.

Sincerely,

Paul Courtois

---

<div class="post-metadata">

**Author:** ![Injeyan\_Kostas](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/injeyan_kostas/32/263_2.png) [@Injeyan\_Kostas](https://community.f5.com/u/Injeyan_Kostas)\
**Post date:** [September 4, 2025, 6:21pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504/2 "2025-09-04T18:21:09Z")

</div>

Hello,

Indeed it’s as simple as creating a new server SSL profile and assign it to VS.

You will need to set server certificate to require under server authentication and select the appropriate trusted CA. You have to upload the CA chain beforehand.

Check this [myF5](https://my.f5.com/manage/s/article/K14806#subsect3)

---

<div class="post-metadata">

**Author:** ![pcourtois](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/pcourtois/32/23197_2.png) [@pcourtois](https://community.f5.com/u/pcourtois)\
**Post date:** [September 4, 2025, 6:45pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504/3 "2025-09-04T18:45:23Z")

</div>

Good day my friend.&nbsp; Awesome!&nbsp; Thank you.&nbsp; I’ll try this in my dev environment and update asap.&nbsp; Much appreciated. &nbsp;👊

---

<div class="post-metadata">

**Author:** ![pcourtois](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/pcourtois/32/23197_2.png) [@pcourtois](https://community.f5.com/u/pcourtois)\
**Post date:** [September 4, 2025, 10:08pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504/4 "2025-09-04T22:08:09Z")

</div>

I created a server ssl profile, set the server certificate to “require” and set the appropriate trusted CA in Server Authentication.&nbsp; (I also have the F5 default “serverssl” profile active on the Virtual Server server profiles).&nbsp; &nbsp;I then updated the bindings on the Web Servers and restarted the service.&nbsp; It broke connections and I see Big-IP LTM logs similar to “Peer cert verify error: self-signed certificate in certificate chain (depth 2; …”.&nbsp; Not sure what is going on here.&nbsp; Change has been reversed for more discovery/testing.

---

<div class="post-metadata">

**Author:** ![Injeyan\_Kostas](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/injeyan_kostas/32/263_2.png) [@Injeyan\_Kostas](https://community.f5.com/u/Injeyan_Kostas)\
**Post date:** [September 4, 2025, 11:27pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504/5 "2025-09-04T23:27:04Z")

</div>

You mean you applied 2 server SSL profiles?

Can you use only the new one? If no you need to let VS know which one to use in each request.

---

<div class="post-metadata">

**Author:** ![Injeyan\_Kostas](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/injeyan_kostas/32/263_2.png) [@Injeyan\_Kostas](https://community.f5.com/u/Injeyan_Kostas)\
**Post date:** [September 5, 2025, 2:10pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504/6 "2025-09-05T14:10:35Z")

</div>

I just did the same in my Lab and worked fine

---

<div class="post-metadata">

**Author:** ![pcourtois](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/pcourtois/32/23197_2.png) [@pcourtois](https://community.f5.com/u/pcourtois)\
**Post date:** [September 5, 2025, 4:41pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504/7 "2025-09-05T16:41:03Z")

</div>

Happy Friday.&nbsp; Thanks for the suggestion.&nbsp; I have to keep the default serverssl profile on the VS as we have multiple applications running on the same VS.&nbsp; The new serverssl profile I’ve created is specifically for our internal web server pools.

How do I tell the VS which profile to use, iRule or in the ssl profile?

---

<div class="post-metadata">

**Author:** ![Injeyan\_Kostas](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/injeyan_kostas/32/263_2.png) [@Injeyan\_Kostas](https://community.f5.com/u/Injeyan_Kostas)\
**Post date:** [September 5, 2025, 4:53pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504/8 "2025-09-05T16:53:23Z")

</div>

Happy Friday to yoo too @pcourtois

irule is you friend in this case  
check this [myF5](https://my.f5.com/manage/s/article/K13452)

```tcl
when HTTP_REQUEST {
    set hostname [getfield [HTTP::host] ":" 1]
}
when SERVER_CONNECTED {
    switch -glob [string tolower $hostname] {
      "sitea.com" {
          SSL::profile serverssl-siteA
      }
      "siteb.com" {
          SSL::profile serverssl-siteB
      }
      default {
        #default serversssl profile to be selected if Host header value cannot be matched with predefined values
        SSL::profile serverssl
      }
    }
}

```

---

<div class="post-metadata">

**Author:** ![pcourtois](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/pcourtois/32/23197_2.png) [@pcourtois](https://community.f5.com/u/pcourtois)\
**Post date:** [September 5, 2025, 4:55pm UTC](https://community.f5.com/t/f5-big-ip-trust-internal-ca-chain-certificates-for-web-servers/76504/9 "2025-09-05T16:55:44Z")

</div>

Copy that.&nbsp; You ROCK!&nbsp; Thank you.&nbsp; I’ll give this a try and update.
