# Using two certificates with SNI and IP as common name

**URL:** <https://community.f5.com/t/using-two-certificates-with-sni-and-ip-as-common-name/52732>\
**Category:** Technical Forums\
**Tags:** security, big-ip, certificate, ltm, sni\
**Created:** [January 20, 2022, 10:46am UTC](https://community.f5.com/t/using-two-certificates-with-sni-and-ip-as-common-name/52732 "2022-01-20T10:46:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yonatan](https://avatars.discourse-cdn.com/v4/letter/y/eb9ed0/32.png) [@yonatan](https://community.f5.com/u/yonatan)\
**Post date:** [January 20, 2022, 10:46am UTC](https://community.f5.com/t/using-two-certificates-with-sni-and-ip-as-common-name/52732/1 "2022-01-20T10:46:33Z")

</div>

Hi all,

I have a VS which client access using both FQDN and IP and I need it to be HTTPS.

I have a legitimate cert for the FQDN (wildcard) and I’ve created a certificate for the IP address using a CA we have inhouse.

I’ve also included SAN values for DNS and IP in this cert.

When I attach each certificate individualy to the VS and try to access it accordingly, everything works fine, so I know the certs are legit.

When I put both certs in the VS and configure their SSL profile with Default SNI and ServerName, it also selects the FQDN cert, even if the client access using IP address.

Any suggestions why this happens?

Using version 14.1.4.5.

Thanks!

---

<div class="post-metadata">

**Author:** ![Nikoolayy1](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/nikoolayy1/32/3589_2.png) [@Nikoolayy1](https://community.f5.com/u/Nikoolayy1)\
**Post date:** [January 26, 2022, 10:49am UTC](https://community.f5.com/t/using-two-certificates-with-sni-and-ip-as-common-name/52732/2 "2022-01-26T10:49:40Z")

</div>

Check the bug tracker but your settup is strange as the idea behind SNI is the same server IP address to be used by the server that host different domains:

> **[myF5](https://my.f5.com/manage/s/)**

[https://community.f5.com/t5/technical-articles/how-to-troubleshoot-sni/ta-p/281658](https://community.f5.com/topic/281658)

Also is the wildcard cert the default SNI cert? Do your client support SNI (for certificates that are not using the IP address do the clients match them correctly and only the one with the IP address is having issues)?

---

<div class="post-metadata">

**Author:** ![Jim\_M](https://avatars.discourse-cdn.com/v4/letter/j/b2d939/32.png) [@Jim\_M](https://community.f5.com/u/Jim_M)\
**Post date:** [March 14, 2022, 5:59am UTC](https://community.f5.com/t/using-two-certificates-with-sni-and-ip-as-common-name/52732/3 "2022-03-14T05:59:45Z")

</div>

How do you set the default SNI cert
