Forum Discussion

Thiyagu_343098's avatar
Thiyagu_343098
Icon for Nimbostratus rankNimbostratus
Jul 04, 2018

Required configruation change to add two SSL profile to a VIP

Hello, For the same LB VIP we have two names and I have to add the SSL profile for both the SAN name to the same VIP.

 

Could you please help me to know the configuration change required to add the two SSL profile to a VIP?

 

Regards, Thiyagu

 

6 Replies

  • You don’t need to change the configuration of the VIP or ssl profile.

     

    You need to add SAN while creating the ssl certificate. If the current certificate was signed by your internal certificate authority, create a new one. If it’s from third party vendor, generate a new CSR with SAN amd contact them. Let me know if it works.

     

    -Harsha.

     

  • Hi Thiyagu,

     

    If you want to assocaited 2 SSL profil to the same VS you can follow this steps.

     

    So suppose you have this 2 ssl profil:

     

    • Profil A: myhost.mydomain.com
    • Profil B: *.mydomain2.com

    First of in your profil you have to set the same: - Ciphers (To begin let the 2 profil at Default). - Renegotiation will be checked on both profil. - try to set the same Parent Profile in both profil (clientssl for example).

     

    Then in Profil A set "Server Name" at "myhost.mydomain.com"

     

    And in profil B set "Server Name" at "*.mydomain2.com" and check "Default SSL Profile for SNI".

     

    When you set 2 ssl profil or more you have to have an Default SSL Profile for SNI.

     

    Regards

     

    • Ajit's avatar
      Ajit
      Icon for Altostratus rankAltostratus

      Hello Thiyagu,

       

      Is your issue resolved now? Did the provided solution work for you? Please update.

       

      Regards,

       

      Ajit

       

    • Ajit_128420's avatar
      Ajit_128420
      Icon for Nimbostratus rankNimbostratus

      Hello Thiyagu,

       

      Is your issue resolved now? Did the provided solution work for you? Please update.

       

      Regards,

       

      Ajit