Forum Discussion

Bhuvanad43_3603's avatar
Bhuvanad43_3603
Icon for Nimbostratus rankNimbostratus
May 03, 2018

Chain certificate F5

Hi, Which certificate needs to be uploaded in the Chain field while creating SSL profiles, i have a single pfx with the below certs 1.global root CA 2.SHA2 secure server CA 2.organisation specific CA I have added this cert in Certificate and Key field, which is to be added in Chain for SSL profiles

 

3 Replies

  • that would be a certificate that can help verify the chain of trust. public CAs normally share the location of these chain certificates

     

    additionally, see K13302: Configuring the BIG-IP system to use an SSL chain certificate (11.x - 13.x)

     

  • Hello,

    When you create a SSL client Profil you have to set certificate and the whole chain.

    example:

    your certificate : myapp.mydomain.com

    your chain: chain+root

    So you can directly import your PFX from F5 GUI (System ›› File Management : SSL Certificate List ›› Import SSL Certificates and Keys) and set import type to "PKCS12". Normaly it will import you all (cert, chain and key). Just check after creation that your certificate contain your certificate and chain...

    Next you have to create your profil ssl client and set your key and certificate following the name that you set in steps before.

    Let me now if you need additional information.

    Regards.