DigiCert KnowledgeBase - Technical Support-hero

Knowledge Base

Installation Instructions for F5 BIG-IP version 11.x

Solution ID : SO22290
Last Modified : 09/17/2024

PROTECT YOUR BRAND AND YOUR USERS WITH A DIGICERT VERIFIED MARK CERTIFICATE.

This article provides installation instructions for F5 BIG IP 11.x. If you are not able to perform the steps on your server, DigiCert recommends to contact the server vendor or the organization which supports F5.

Step 1. Obtain the SSL Certificate

  1. Log into your CertCentral account. Enter in your Username and Password.
  2. Click Sign In.
  3. From the list, select the corresponding certificate to download.
  4. Under Available Actions in the bottom section, click on Download your certificate.
  5. Confirm the certificate details, then click the Get Started button.
  6. Select the Server platform and Server version from the drop-down menus where the certificate will be installed to.
    NOTE: If you are not sure of the server platform, choose Other. This will give you the x.509 version of the certificate.
  7. Click the Download button
  8. A prompt window will appear to save a .zip file which will contain all necessary certificates and additional documents and/or information for installation.

Step 2. Install the SSL Certificate

  1. On the left panel, navigate to System >  File Management
  2. Choose SSL Certificate List
  3. From the list, click on the pending request (the label from when you generated the CSR)
  4. Click on Import
  5. Select Upload file
  6. Click on Browse
  7. Locate the SSL certificate file then click OK
  8. Click on Import

Step 3. Download and Import the Intermediate CA certificate 

  1. Download the Intermediate CA certificate from this link: INFO657.
    Select the appropriate Intermediate CA certificate for your SSL Certificate type.

    NOTE: If you are unsure of which product you have purchased, please review the following knowledge base solution:  SO13499.
  2. Copy the Intermediate CA certificate and paste it on Vi or Notepad.
  3. Make sure there are 5 dashes to either side of the BEGIN CERTIFICATE and END CERTIFICATE and that no white spaces, extra line breaks or additional characters have been inadvertently added.
  4. Save the file as Intermediate.pem.
  5. On the left panel, navigate to System > File Management > SSL Certificate List
  6. Click on Import (button to the right)
  7. Select Certificate on the dropdown. Choose Create New and give a name for the certificate in the box below.
  8. Choose Upload File and click Browse
  9. Locate the Intermediate.pem file then click OK
  10. Click on Import

Step 4. Updating the SSL profile

  1. On the left panel, navigate to Local Traffic Profiles > SSL > Client.
  2. From the list, select the SSL profile for your website.
  3. For Configuration, choose Advanced from the dropdown.
  4. Select from the dropdown the Certificate and Key imported from the previous step.
  5. Under Chain, select from the dropdown the CA intermediate previously imported.
  6. To apply the changes, scroll down to the bottom of the page and click Update.
  7. Verify your installation with the DigiCert SSL Tools.

F5 Support

For additional information, refer to F5's KB solution: SOL13302