Forum Discussion

Kevin_McD_51656's avatar
Kevin_McD_51656
Icon for Nimbostratus rankNimbostratus
Jun 17, 2009

SSL Certificate Import

Hi all... post 1 here, so please go easy on me. Tried searching for this topic, but not much success:

 

 

Trying to import an SSL certificate, to offload HTTPS for a Sharepoint web farm using BIGIP LTM 6400 9.3.1. The cert currently is installed on WFE 1 (Win2008, IIS7).

 

 

If I export the cert from IIS, the only option I have is to export as password-protected .PFX. When I import certificate (Local Traffic >> SSL Certificates >> Import SSL Certificates and Keys), I get:

 

IMPORT FAILED: CERTIFICATE/KEY MISMATCH

 

 

If I export from MMC>Certificates, including the private key, again the only option I have is to export as password-protected .PFX. Same results when I import certificate (Local Traffic >> SSL Certificates >> Import SSL Certificates and Keys), I get:

 

IMPORT FAILED: CERTIFICATE/KEY MISMATCH

 

 

If I export from MMC>Certificates, this time NOT including the private key, and export as .CER. Same results when I import certificate (Local Traffic >> SSL Certificates >> Import SSL Certificates and Keys), I get:

 

IMPORT FAILED: CERTIFICATE/KEY MISMATCH

 

 

I've confirmed that the name on the cert matches what I've entered for "Certificate Name" on the import screen, and neither time have I been prompted to supply the password.

 

 

I was told by support that I needed to upgrade to get the password-protected file to work, so we went to 10.0.1 on a test system running the same config as production...now I get:

 

 

If I export from MMC>Certificates, including the private key, again the only option I have is to export as password-protected .PFX. Same results when I import certificate (Local Traffic >> SSL Certificates >> Import SSL Certificates and Keys), I get:

 

IMPORT FAILED: CERTIFICATE/KEY MISMATCH

 

 

If I export from MMC>Certificates, this time NOT including the private key, and export as .CER. This time it imports successfully, but still doesn't prompt me for a password.

 

 

What am I doing wrong on the 9.3.1 version?

 

How do I separate the private key from the .PFX to import into another area?

 

3 Replies

  • Not sure if this is what you need but check it out. It worked for me!

     

     

    http://vegan.net/lb/archive/05-2002/0018.html
  • Go to tech.f5.com and look up solution 6549. I think that will do what you need.