Forum Discussion

bac81987_341588's avatar
bac81987_341588
Icon for Nimbostratus rankNimbostratus
Apr 12, 2018

Importing SSL Cert/ Possible Downtime

Good morning,

 

I've been tasked to import an SSL Certificate onto our F5's. It contains DNS entries for our CAS Exchange Servers. I'm using the following Article to catch me up to speed:

 

https://support.f5.com/csp/article/K146203

 

I haven't come across it yet, but if I replace our current SSL Cert with this new one, does it take effect immediately? Also, is there any down time needed for the F5's after importing and applying the cert?

 

1 Reply

  • The new cert will immediately replace the old cert and will be used for all new connections moving forward. We will not renegotiate existing connections. This should not impact traffic. From the SOL you link:

     

    Important: Existing connections continue to use the old SSL certificate until the connection completes, are renegotiated, or TMM is restarted.

     

    Note: When using this procedure to import a renewed SSL certificate, you must choose a unique Name. Consider appending the current year for easier accountability. For example, name the SSL certificate example_2017.

     

    Impact of procedure: Performing the following procedure should not have any impact to the existing traffic and new traffic will utilize the new certificate.