Ask a Question

Advanced Search

Solution ID : SO25659

Last Modified : 06/12/2019

Installation Instructions for F5 Big IP 9.x -10.x


This document provides instructions for installing SSL Certificate on F5 Big IP 9.x -10.x.
Step 1: Download the SSL Certificate & Intermediate CA Certificate
  1. Download your certificate from the unique secure link we provide your technical contact via order fulfillment email.
  2. The ZIP file you downloaded contains the following certificates:
    • SSL certificate (i.e. ssl_certificate.crt, also known as end entity certificate, public key certificate, digital certificate or identity certificate).
    • Intermediate CA certificate (i.e. IntermediateCA.crt, also known as chained certificate or signer/issuer of the SSL certificate).
  3. Unzip the files onto the server where you will install the certificate.

Step 2: Install the SSL Certificate

  1. Log in to the Configuration utility
  2. Click System > File Management > SSL Certificate List.
  3. Click Import.
  4. From the Import Type list, select Certificate.
  5. For the Certificate Name setting, do one of the following:
    • Select the Create New option, and type a unique name in the field.
    • Select the Overwrite Existing option, and select a certificate name from the list.
  6. For the Certificate Source setting, do one of the following:
    • Select the Upload File option, and browse to the location of the SSL certificate file (i.e. ssl_certificate.crt, as described in Step 1).
    • Select the Paste Text option, and paste the certificate text copied from another source.
  7. Click Import.

If you are unable to use these instructions for your server, Symantec recommends that you contact either the vendor of your software or an organization that supports F5 Big IP.

Step 3: Install the Intermediate CA Certificate

  1. Log in to the Configuration utility.
  2. Click Local Traffic > SSL CertificatesImport and select Certificate from the Import Type menu.
  3. Click the Create New option.
  4. Type a unique name for the Certificate Name.
  5. Click Browse and navigate to select the Intermediate CA certificate file (i.e. IntermediateCA.crt, as described in Step 1).
  6. Click Open.
  7. Click Import.
Step 4: Configure an SSL Client Profile to use the Intermediate CA Certificate
  1. Log in to the Configuration utility.
  2. Click Local TrafficProfiles and select Client from the SSL menu.
  3. Select the Client SSL profile you wish to configure.
  4. Select Advanced from the Configuration menu.
  5. Select the appropriate chain certificate from the Chain dropdown box.
  6. Click Update.

Step 5: Verify certificate installation

  1. Verify your installation with the DigiCert Installation Checker


          For additional information, see F5 Support website.