Forum Discussion

Ryan_34424's avatar
Ryan_34424
Icon for Altostratus rankAltostratus
Jul 13, 2018

BIG-IQ 6.0.0 :: Management Interface Certificate :: Trusted CA's

Anybody know how to replace the existing self-signed certificate on the management interface of the BIG-IQ platform with something signed by a CA? I attempted K52425065 however that did not work (for what it's worth, the "applies to" details of the article did not include 6.0.0).

 

Also - our proxy performs SSL inspection, and the BIG-IQ does not trust its CA. Because of this it cannot connect outbound such as to iHealth. Anybody know how to add a trusted certificate authority for outbound connections?

 

1 Reply

  • So in regards to the first part... K52425065 gives you options for using your own certificate filenames. In order for this to work it has to be EXACTLY server.crt and server.key (so, not your own certificate filenames). Making that change, it then worked properly. However the article states to restart httpd when you really need to restart webd.

     

    Still trying to figure out the trusted CA.