Forum Discussion

senthil147_1421's avatar
senthil147_1421
Icon for Nimbostratus rankNimbostratus
Feb 17, 2018

Device certificate replace in HA Sync group 13.x

Team

 

i need to replace self signed device certificate with CA signed certificate. But the devices are in HA group and running 13.1 version . If i renew the certificate will it break HA ? if yes how to replace the device certificate in HA sync group.

 

1 Reply

  • Hello,

     

    The device certificate is independent of the trust certificates used for the DSC configuration. You should be fine to replace it at any time.

     

    One scenario that you need to be concerned about the device certificate is if you're using BIG-IP DNS (GTM), which uses that certificate as part of the trust for the iQuery protocol. If you switch to a CA signed cert then you should install the CA cert in the BIG-IP DNS Trusted Server Certificates list.