Skip to content

F5 BIG-IP LTM

Tip

Before proceeding, verify that the machine is already created in Certificate Manager - SaaS. Also, ensure that you’ve completed the prerequisite configuration steps for the F5 BIG-IP LTM machine.

You can present the certificate on an application traffic SSL profile, or on the device administration page. When you provision to an application traffic SSL profile, you can use an existing SSL profile on your F5, or you can use Certificate Manager - SaaS to create a new SSL profile for you. The steps below walk you through these scenarios.

  1. Sign in to Certificate Manager - SaaS.
  2. Click Installations > Machines.
  3. Locate the F5 BIG-IP LTM machine that you want to provision a certificate to.
  4. At the right end of that machine's row, in the Actions column, click the actions menu (⋮), and then click Provision.

    What if Provision is unavailable

    If Provision is unavailable, check that the machine's status is Verified. Provisioning is also unavailable if you don't have permission to provision certificates, or to act on that particular machine.

  5. In the Search a certificate by name, expiration or fingerprint field, begin typing the certificate name you want to provision. Click the certificate when you see it listed.

    Verify that you've selected the correct certificate by reviewing the values that appear below the field.

  6. In the Certificate Name field, enter the name for this certificate as you want it to appear on your F5.

    What if the name is already in use on the F5?

    When provisioning a certificate to the F5, Certificate Manager - SaaS checks to see if the name you enter in this field is already in use.

    • If the name you enter isn't in use, Certificate Manager - SaaS will use it.
    • If the name is in use, Certificate Manager - SaaS checks to see if it's the same certificate. If so, Certificate Manager - SaaS uses the certificate that is already on the F5.
    • If the name is in use, but it's a different certificate, then Certificate Manager - SaaS creates a new certificate. A unique certificate name will be generated using a combination of the certificate name entered in this field, the expiration date from the certificate, and a unique numerical value, such as my-cert-name_22Oct05_3117.
  7. From the Supporting Certificates drop-down, choose how the certificate's supporting certificates are stored on your F5.

    Supporting certificates are the CA certificates that prove your website certificate was issued by a trusted authority. Clients need them to verify the site.

    • Included with certificate – Installs the website certificate and its supporting certificates together, in a single certificate file on the F5.
    • Separate file – Installs the supporting certificates in their own certificate file, which you name in the Chain Bundle Name field.
    • Do not install – Installs only the website certificate and omits the supporting certificates.

    Note

    This field is blank until you choose an option. If you leave it blank, Certificate Manager - SaaS selects Separate file when the installation has a Chain Bundle Name, and Included with certificate when it doesn't. Either way, the supporting certificates are installed.

    Important

    Choose Do not install only when you're certain the clients connecting to this site already trust your issuing CA.

  8. (Separate file only) In the Chain Bundle Name field, enter the name for the CA certificate bundle as you want it to appear on your F5.

    This field is shown only when Supporting Certificates is set to Separate file, or when the installation already has a chain bundle name from a previous provision or from discovery.

    Note

    A Chain Bundle Name is required when you select Separate file. Save stays unavailable until you enter one, or until you choose a different Supporting Certificates option.

    What if the bundle name is already in use on the F5?
    • If the bundle does not exist, Certificate Manager - SaaS creates it with the supporting certificates.
    • If every supporting certificate is already in the bundle, Certificate Manager - SaaS makes no changes and provisioning continues. Extra certificates already in the bundle, or a different order, don't cause a failure.
    • If the bundle is missing one or more of the supporting certificates, Certificate Manager - SaaS adds the missing ones to the existing bundle and reinstalls it, keeping the certificates that are already there.
  9. From the Binding Type drop-down, select where you want the certificate to be presented:

    • Application Traffic (SSL Profile) – Presents the certificate on a client SSL or server SSL profile that handles application traffic. This is the default.
    • Device Administration – Presents the certificate on the device administration page, which is served by the F5 management web service (httpd).

    Note

    The fields that follow change based on which option you choose here, except Partition, which applies to both. Installations created before Binding Type was added continue to use Application Traffic (SSL Profile).

  10. (Application Traffic only) From the Profile Type drop-down, select either Client SSL Profile or Server SSL Profile, depending on the type of F5 profile you're provisioning to.

  11. In the Partition field, enter an F5 partition name. This partition must already exist on the F5. Leaving this field blank will default to the F5's Common partition.

    Note

    The partition name is case sensitive.

  12. (Application Traffic only) In the Parent Profile field, enter the name of the parent profile you want to associate with the SSL Profile.

    Note

    If you're using an existing SSL Profile in the next step, this field will be ignored. Certificate Manager - SaaS will not modify the parent profile of existing SSL profiles.

  13. (Application Traffic only) In the SSL Profile field, enter an SSL profile name. This can be either a name that is already in use on the F5 partition, or a new name.

    What happens if the name is already in use?

    If the profile name you enter already exists in the F5 partition you entered previously (see the Partition step above), then Certificate Manager - SaaS will provision the certificate to that profile. Otherwise, Certificate Manager - SaaS creates a new profile using the name you enter here.

  14. (Application Traffic only) For Client SSL Profiles, you can optionally enter an alternative DNS name for Server Name Indication in the SNI field.

    Warning

    If you're editing an existing SSL profile, any current Server Name value will be overwritten if you enter a value here.

    Note

    The Virtual Server Name(s) list shows the virtual servers on the F5 machine that currently use the SSL profile you entered. Because an SSL profile can be applied to multiple virtual servers, this list helps you verify that you’re provisioning the certificate to the correct profile.

  15. (Device Administration only) To make the new certificate take effect immediately, select Restart the HTTP service. Certificate Manager - SaaS restarts the F5 management web service (httpd) after it installs the certificate, and then confirms that the service comes back online.

    Warning

    Restarting the service briefly disconnects the F5 management session. Anyone signed in to the F5 management interface is signed out and must sign in again.

    Note

    If you leave Restart the HTTP service as its default setting (cleared), the certificate is installed but is not presented until the next time the httpd service restarts.

  16. If you don't want the certificate to be pushed when you save, turn off Push certificate on save. This toggle is on by default.

  17. Click Save.

    Want to schedule your provisions?

    Schedule your provisions daily, weekly, or monthly. Learn more

After saving, the certificate is pushed to the F5 and an installation is created on the Installations tab. For Application Traffic (SSL Profile) bindings, the certificate is pushed to the SSL profile that you specified; if you created a new SSL profile, that profile is now ready to be assigned to a virtual server or HTTPS health monitor on the F5. For Device Administration bindings, see Provisioning to the device administration page.

Certificate Manager - SaaS then connects back to the F5 to confirm that the device is serving the certificate, and updates the installation's status with the result. See Verifying the installation.

How discovery records existing SSL profiles

When Certificate Manager - SaaS discovers your F5, it records how each SSL profile already stores its supporting certificates, so that later provisioning reproduces the same arrangement:

  • A profile that references a separate chain bundle is recorded as Separate file, using that bundle's name.
  • A profile with no separate chain bundle is recorded as Included with certificate.

Discovery never records Do not install, because omitting the supporting certificates is always an explicit choice you make.

Installations created or discovered before the Supporting Certificates field was added don't have a recorded setting. For those, Certificate Manager - SaaS applies the same rule the next time it provisions: Separate file if the installation has a Chain Bundle Name, otherwise Included with certificate. Their supporting certificates are installed again without you having to re-run discovery or edit the installation.

The Chain Bundle Name remains optional, so a profile discovered without a chain bundle can still be renewed and reprovisioned without you providing one.

Existing installations can get a new certificate name

When an installation's certificate is stored on the F5 without its supporting certificates, and Certificate Manager - SaaS now installs it as Included with certificate, the new certificate file differs from the one already on the F5. This is true even when the website certificate itself hasn't changed. Certificate Manager - SaaS therefore adds the certificate under a generated name, such as my-cert-name_22Oct05_3117, and presents that certificate on the SSL profile. For how generated names work, see the Certificate Name step above.

Certificates Certificate Manager - SaaS can't read during discovery

Some certificates use algorithms that Certificate Manager - SaaS can't read, such as CA certificates issued on Brainpool elliptic curves. When discovery reads a PEM certificate file:

  • If a supporting certificate can't be read, Certificate Manager - SaaS skips that certificate and records the installation with the certificates it could read. Discovery continues.
  • If the website certificate can't be read, Certificate Manager - SaaS skips that installation, and it doesn't appear in the inventory.

If a certificate in a DER (binary) certificate file can't be read, discovery stops with an error.

Automatic certificate generation management

Each time you renew and reprovision a certificate to an F5 BIG-IP LTM profile, Certificate Manager - SaaS automatically manages certificate generations on the F5 device.

  • The newly provisioned certificate becomes the active version.
  • The previously active certificate is retained as a rollback version.
  • Older certificate generations deployed by Certificate Manager - SaaS are automatically removed, as long as they are not currently assigned to another SSL profile.

This cleanup happens automatically in the connector and does not require additional configuration.

Verifying the installation

An F5 can accept a certificate without serving it. For example, a script on the F5 might rename the certificate after it's installed, or the SSL profile might still reference the previous certificate. To catch this, after Certificate Manager - SaaS installs the certificate and binds it to the SSL profile, it reads back from the F5 and checks the following, in order. It uses the partition from the installation, or Common if you left Partition blank.

  1. The certificate exists in the partition.
  2. A private key with the same name as the certificate exists in the partition. Certificate Manager - SaaS checks only that the key exists. It doesn't read the key or confirm that it pairs with the certificate.
  3. The SSL profile exists in the partition and references the certificate. For a client SSL profile, the certificate can be in any of the profile's certificate key chains.
  4. The certificate on the F5 is the certificate that Certificate Manager - SaaS provisioned. Certificate Manager - SaaS reads the certificate file from the F5 and compares its fingerprint with the provisioned certificate's. If the file also holds supporting certificates, only the website certificate is compared.

The installation's status on the Installations tab shows the result:

  • Validated – Every check passed.
  • Failed – A check failed. Certificate Manager - SaaS stops at the first check that fails.

Verification doesn't change anything on the F5. When an installation shows Failed, Certificate Manager - SaaS doesn't roll back or retry the provisioning.

To find out which check failed, open the event log and find the Onboard Validation Failed event for the installation. The event's message names the cause:

  • The certificate or private key wasn't found in the partition.
  • The SSL profile wasn't found in the partition.
  • The SSL profile references a different certificate. The message names the certificate that the profile references and the one that was expected.
  • The certificate on the F5 isn't the certificate that was provisioned. The message gives the thumbprint and serial number of the certificate on the F5, and the thumbprint of the certificate that was provisioned.

Certificate Manager - SaaS skips some checks in these cases:

  • Device Administration bindings have no SSL profile, so Certificate Manager - SaaS skips all of the checks and the installation shows Validated.
  • If Certificate Manager - SaaS has no fingerprint on record for the certificate, it skips the fourth check. This can happen for installations provisioned before Certificate Manager - SaaS began recording fingerprints.

Provisioning to the device administration page

When you select Device Administration, Certificate Manager - SaaS installs the certificate and private key onto the files that the F5 management web service (httpd) serves. The F5 configuration already points to these files, so no further configuration is required on the device.

When you provision to the device administration page, note the following:

  • Provisioning to the device administration page requires an F5 account with administrator permissions. If the account does not have them, provisioning fails with a message stating that administrator permission is required.
  • Set Supporting Certificates to Included with certificate or Do not install. The device administration page is served from a single certificate file and has no separate chain file, so Separate file doesn't apply here: Certificate Manager - SaaS installs only the website certificate on the management web service, and the separate chain bundle is created on the F5 but left unused.
  • Before overwriting the files, Certificate Manager - SaaS archives the current certificate and key on the device in /var/tmp. The archive is readable only by its owner, because it contains the management private key.
  • Certificate Manager - SaaS keeps the three most recent archives on the device and removes older ones.
  • If the certificate is written but the private key cannot be, Certificate Manager - SaaS restores the archive it created at the start of the operation so that the management web service can still start, and reports provisioning as failed. You should retry it. Recovery depends on that archive:
    • If the restore succeeds, the device keeps its previous certificate and key.
    • If the restore fails, the error message names the archive to restore manually.
    • If no archive was created at the start (archiving is best-effort), Certificate Manager - SaaS cannot roll back automatically; the error message tells you to restore the previous certificate and key manually before the next httpd restart.
  • Certificates that secure the device administration page are not returned by machine discovery. Discovery reports certificates that are bound to application traffic SSL profiles.
  • Certificate Manager - SaaS doesn't verify the installation for device administration bindings. The installation shows Validated once the certificate is installed.