Forum Discussion

kridsana_52318's avatar
kridsana_52318
Icon for Nimbostratus rankNimbostratus
Aug 23, 2016

What use of ca-bundle? Can I remove it?

Hi everyone

 

As subject , What use of ca-bundle?

 

Can I remove it? because It's always alert customer that some Certificate in ca-bundle is expired. and remove only "that expired certificate" is troublesome (many box , many expired cert)

 

Or Is there a way that we can config user-alert to not alert "ca-bundle certificate" expiration?

 

Thank you very much

 

6 Replies

  • right now we use this SOL to monitor certificate expiration

     

    https://support.f5.com/kb/en-us/solutions/public/14000/300/sol14318.html

     

    Not sure if it can exclude ca-bundle?

     

  • As long as you are not utilizing the ca-bundle as part of any client ssl profile, I think it is okay to remove it.

     

  • Could you share the Iapp CA-Bundle? Is no longer available in downloads or through the pointer of the document f5-ca-bundle-dg.pdf.

     

    Thank you

     

  • Hello Nobody96, the iApp is still in the current zip file on . As mentioned in the deployment guide, you must go to the "RELEASE CANDIDATES" folder inside the zip file, and there you'll find the CA bundle iApp. Let us know if you are still having troubles.