Forum Discussion

fat_138651's avatar
fat_138651
Icon for Nimbostratus rankNimbostratus
May 05, 2015

Device Trust BigIp 6900

Hi,

 

I am currently trying to set up device trust for a pair of BigIP 6900 using 11.5.2 HF1. I set up all the basic stuff like vlans, IPs etc. und now I wanted to create a self signed certificate with my company informations to create the device trust.

 

For that I tried to renew the device certificate, but I get the following error message on both machines:

 

com.f5.tmui.util.Syscall$CallException: Error: Failure to create certificate server with error: Key file named "server.key" must exist to create a corresponding certificate..

 

I seem to have an existing server.key, but its only 1024 bit in size.

 

Can you tell me what's my problem and how to solve it? Is my problem, that the server.key is to small? But how can I create a bigger one (e.g. 2048)?

 

Thanks in advance

 

Regards, Thorsten

 

4 Replies

  • Hi Thorsten,

     

    actually not sure whats causing this for you, but have a look at - it details steps to generate a new device certificate and key as well, so once done you´re good to proceed :-)

     

    Kind regards, Benedikt

     

  • Joe_M's avatar
    Joe_M
    Icon for Nimbostratus rankNimbostratus

    I am having the same issue on the same version. I did the command in the SOL you listed there and then tried to do it again in the WebUI and still got the same error. I am seeing if I can find a way to fix it but it might be a bug. If I can't figure it out, I will be opening a ticket with F5.

     

  • I switched both devices off over night, and now the error is gone.

     

    Maybe it is just a bug in 11.5.2. I hope 11.6.1 will come out soon, and I will try it again with the new Version.

     

  • I had the same problem when I specified a subject alternate name. I removed that field and the create worked.