Ask a Question

Solution ID : SO25718

Last Modified : 05/02/2018

Installation Instructions for F5 Big IP version 11

Solution

This document provides instructions for installing SSL Certificate on F5 Big IP 11.

Step 1: Download the SSL Certificate & Intermediate CA Certificate
  1. Download your certificate from the unique secure link we provide your technical contact via order fulfillment email.
  2. The ZIP file you downloaded contains the following certificates:
    • SSL certificate (i.e. ssl_certificate.crt, also known as end entity certificate, public key certificate, digital certificate or identity certificate).
    • Intermediate CA certificate (i.e. IntermediateCA.crt, also known as chained certificate or signer/issuer of the ssl certificate).
  3. Unzip the files onto the server where you will install the certificate.
     

Step 2. Install the SSL Certificate

  1. Log in to the Configuration utility.
  2. Navigate to System > File Management > SSL Certificates List and click Import.
  3. From the Import Type list, select Certificate.
  4. In the Certificate Name section, click Create New.
  5. In the Certificate Name box, type a name for the SSL certificate.
  6. In the Certificate Source section, click either Upload File or Paste Text the SSL certificate (i.e. ssl_certificate.crt, as described in Step 1).
  7. Click Import.
     

If you are unable to use these instructions for your server, Thawte recommends that you contact either the vendor of your software or an organization that supports F5 Big IP.
 

Step 3: Importing an SSL Private Key

  1. Log in to the Configuration utility.
  2. Navigate to System > File Management > SSL Certificates List and click Import.
  3. From the Import Type list, select Key.
  4. In the Key Name section, click Create New.
  5. In the Key Name box, type a unique name for the key.
  6. In the Key Source section, click either Upload File or Paste Text.
  7. Click Import.
     

Step 4: Install the Intermediate CA Certificate

  1. Log in to the Configuration utility.
  2. Click Local Traffic > SSL Certificates and click Import.
  3. Select Certificate from the Import Type menu.
  4. Click the Create New option.
  5. Type a unique name for the Certificate Name.
  6. Click Browse and navigate to select the Intermediate CA certificate file (i.e. IntermediateCA.crt, as described in Step 1).
  7. Click Open.
  8. Click Import.
     

Step 5: Configure an SSL Client Profile to use the Intermediate CA Certificate

  1. Log in to the Configuration utility.
  2. Click Local Traffic.
  3. Click Profiles.
  4. Click SSL.
  5. Click Client or Server.
  6. Click the name of the Client SSL or Server SSL profile.
  7. From the Configuration box, select Advanced.
  8. If it is not already selected, select the Chain check box.
  9. From the Chain box, select the appropriate chain certificate.
  10. To save the modifications, click Update.
     

Step 6: Verify certificate installation

  1. To verify if your certificate is installed correctly, use the Thawte Installation Checker

F5 

         For additional information, see F5 Support website.