# How to modify client-ssl on multiple VS using TMSH

**URL:** <https://community.f5.com/t/how-to-modify-client-ssl-on-multiple-vs-using-tmsh/47949>\
**Category:** Technical Forums\
**Tags:** tmsh, ltm, application-delivery\
**Created:** [November 25, 2020, 8:18pm UTC](https://community.f5.com/t/how-to-modify-client-ssl-on-multiple-vs-using-tmsh/47949 "2020-11-25T20:18:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Al\_Estrellas](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@Al\_Estrellas](https://community.f5.com/u/Al_Estrellas)\
**Post date:** [November 25, 2020, 8:18pm UTC](https://community.f5.com/t/how-to-modify-client-ssl-on-multiple-vs-using-tmsh/47949/1 "2020-11-25T20:18:53Z")

</div>

Hi,

I was able to get the list of virtual servers using cert1 for example by list and grep.

Now, I want to use TMSH to use the CLI in replacing client-ssl cert1 to cert2. If I have like 50 VS, how to do that using modify on TMSH?

If I do modify /ltm virtual VSname profile add SSLname context clientside, im getting this error:

“vs has more than one clientssl/serverssl profile with same server name”

If I do delete, im getting this error:

“Syntax Error: “context” is a read-only property”

If I do replace-all-with, cert2 is configured but wipes all other profiles and i don’t want to put alot of config to reconfigure all profiles in a VS.

Is there a 1 line command I can do?

TIA

---

<div class="post-metadata">

**Author:** ![Mayur\_Sutare](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/mayur_sutare/32/5035_2.png) [@Mayur\_Sutare](https://community.f5.com/u/Mayur_Sutare)\
**Post date:** [November 26, 2020, 2:47am UTC](https://community.f5.com/t/how-to-modify-client-ssl-on-multiple-vs-using-tmsh/47949/2 "2020-11-26T02:47:47Z")

</div>

Below command should work to modify SSL Profile on the VS.

**tmsh modify ltm virtual [virtual server name] profiles add { [client-ssl profile name] }**

For the error that you are getting, do you have multiple client SSL on your VS and one of the profile is acting as default SSL? Please refer below articles.

> **[Bug ID 794493](https://cdn.f5.com/product/bugtracker/ID794493.html)**

> **[myF5](https://my.f5.com/manage/s/article/K05426346)**

---

<div class="post-metadata">

**Author:** ![Al\_Estrellas](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@Al\_Estrellas](https://community.f5.com/u/Al_Estrellas)\
**Post date:** [November 26, 2020, 3:05pm UTC](https://community.f5.com/t/how-to-modify-client-ssl-on-multiple-vs-using-tmsh/47949/3 "2020-11-26T15:05:18Z")

</div>

The above solution did not do the trick even I removed the chain, most likely because I am using the same key/certificate just using a different SSL profile to do the test.

I tried using a different key/certificate but also different domain and it worked. On December 2nd week, I’ll get the new/replacement cert and will test the procedure in the KB and see if it works on same domain name different key/cert.

Here’s the commands for reference:

modify /ltm virtual https\_vs&nbsp;profiles add { newcert-clientssl&nbsp;{context clientside } }

modify /ltm virtual https\_vs profiles delete { oldcert-clientssl }

I’ll update this on December when I renew cert and will use a different SSL profile.

Thanks for the help.

---

<div class="post-metadata">

**Author:** ![Sean\_B](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@Sean\_B](https://community.f5.com/u/Sean_B)\
**Post date:** [June 12, 2024, 7:56pm UTC](https://community.f5.com/t/how-to-modify-client-ssl-on-multiple-vs-using-tmsh/47949/4 "2024-06-12T19:56:27Z")

</div>

If you are running a script to swap the clientssl profile of VIP, the below will work (you might need to have a standard where all clientssl profiles actually start with with word clientssl though)

modify /ltm virtual https\_vs profiles delete { clientssl\* }&nbsp;  
modify /ltm virtual https\_vs profiles add { newcert-clientssl {context clientside } }
