SSL/TLS CERTIFICATE F5 BIG IP INSTALLATION


GENERATE CERTIFICATE SIGNING REQUEST FOR F5 BIG I

DOWNLOAD THE CERTIFICATE


First, Select the Download button within the pickup wizard to download your certificate files. That will create a zip file that includes your ServerCertificate.crt: Your signed SSL/TLS certificate and ChainBundle1.crt: The Entrust Certificate chain in one file.

IMPORTING CHAIN AND INTERMEDIATE CERTIFICATES


F5 Big IP Web GUI

1. Open the F5 Big-IP web GUI.

2. Then, from the Main tab, Select System.

GUI Filter

3. Next, Select SSL Certificate List to show the current certificates.

SSL Cert List

SSL Cert List Example

4. Then, Select Import located on the top right of the window.

Click Import

Choose what to import

5. Next, Select Certificate from the Import Type menu.

6. Locate the Certificate Name line and type in EntrustChain. Next to the Certificate Source box browse to upload the ChainBundle1.crt file.

7. Next, Select Import. You will notice that the new certificate will be on the list labeled as EntrustChain.

SSL Cert List

Entrust Chain Highlighted

INSTALLING THE SERVER CERTIFICATES


1. Locate the SSL Certificate List to show all the current certificates.

2. Next, Select the name of your key file when you made your CSR. For the purpose of the example below the key file is shown as MyKey.

MyKey Highlighted

3. Select Import.

Import Key

4. Next, under the Certificate Source box Browse to theServerCertificate.crt file that you downloaded earlier. Then, press Import.

Import Key

Import SSL Certificate

5. You will now see the Server Certificate and Key in the list.

Import SSL Certificate

Server Name On Cert Example

6. Go to the F5 BIG-IP site and locate the Main tab, Select Local Traffic and Select Profiles.

Profiles Highlighted

7. Next, from the menu at the top of the screen Select SSL then Client.

Client Highlighted

8. Then, generate a new SSL profile by selecting Create or Open and Existing SSL profile.

Test Certificate

9. Then, Select Advanced from the Configuration menu.

10. From the Configuration window, Select the box next to Custom.

Advanced Menu

11. Within the Certificate menu, Click your Server Certificate.

12. Next to the Key option, Select the name of your Key from the menu. Your key is the same as the one you created when you made your CSR.

Configuration Menu

13. Lastly, locate the Chain option and Click the EntrustChain that was uploaded earlier. You have completed the installation process. You can also check to make sure your Certificate is installed by going to this link:https://entrust.ssllabs.com

Pick Entrust Chain

GENERATE CERTIFICATE SIGNING REQUEST FOR F5 BIG I
Back To Guides