Ask a Question

Advanced Search

Solution ID : SO13386

Last Modified : 05/31/2019

Certificate Signing Request (CSR) Generation Instructions for F5 BIG-IP Load balancer version 9.x and 10.x


This document provides CSR generation instructions using F5 BIG IP 9.x or 10.x GUI. If you are not able to perform the steps on your server, DigiCert recommends to contact the server vendor or the organization, which supports F5.

NOTE: To generate a CSR, you will need to create a key pair for your server. These two items are a digital certificate key pair and cannot be separated. If you lose your public/private key file or your password and generate a new one, your SSL Certificate will no longer match.

To generate a CSR, perform the following steps:

  1. Launch the F5 BIG IP Web GUI.
  2. Under Local Traffic click SSL Certificates.

  3. Click Create.
  4. Under General Properties give the certificate a name (this name will be used in the future to identify this certificate).
  5. Under Certificate Properties enter the following information:
    • Issuer: Certificate Authority Symantec.
    • Common name: FQDN (fully-qualified domain name) of the server (e.g.,,, or for wildcard certificate *
    • Division: A department name, such as 'Information Technology'.
    • Organization: The full legal name of the organization.
    • Locality, State or Province, Country: City, state, and country where the organization is located. Do not abbreviate.
    • E-mail Address: Your email.
    • Challenge Password, Confirm Password: Enter a password.
  6. Under Key Properties a key size of at least 2048 must be selected.
  7. Click Finished.
  8. Provided will be the text of a Certificate Signing Request file. 
  9. Verify your CSR
  10. Copy and paste the entire body of that file into the enrollment page when prompted.

 Once the certificate has been issued, follow the steps from this link to install it on the server:  INFO165