Forum Discussion

prole92_221949's avatar
May 26, 2016

Checking SSL Certificates using iControl REST API

Hi guys,

 

I'm looking for a way to check if the SSL certificate has expired using iControl REST API. I have already found a way to check all certificates that can be used in SSL Client/Server Profiles with Virtual Servers mgmt/tm/sys/file/ssl-cert endpoint and these are all certificates that can be found in System >> File Management >> SSL Certificate List.

 

I'm also very interested in checking the certificates that are using for config sync between the BIG-IP devices. This is the part where I'm having some issues. I have found the mgmt/tm/cm/cert endpoint that contains dtca.crt and dtci.crt. I'm wondering what these certificates are used for. Can somebody shed some light on it please? In the documentation I have also found mention of server.crt and client.crt that can be found in the /config/httpd/conf directory of the BIG-IP file system. But I haven't managed to find any iControl REST API endpoint that would return some information about these certificates, and I'm not sure what they are used for either.