Forum Discussion

Senthil_Govinda's avatar
Senthil_Govinda
Icon for Nimbostratus rankNimbostratus
Jun 15, 2014

Modify existing Subjective Alernative Name SAN certificate

Dear All,

 

I can search links for new CSR for SAN certificate. Kindly advice in adding new domain to the existing SAN certificate.

 

Thanks

 

7 Replies

  • Senthill,

     

    If you need a add new alternate names to a working certificate on an F5 then goto System -> File -> SSL Certificates.

     

    Click on the working certificate to open it, click renew, add/modify your new subject alternate names in the format DNS:alternate.dns.name

     

    See SOL13471 - Creating SSL SAN Certificates for more information

     

    • Senthil_Govinda's avatar
      Senthil_Govinda
      Icon for Nimbostratus rankNimbostratus
      Hi Kevin, The Version I'm using is 10.2. Hope add/modify will be there for Version 11.
  • I am running 11.5 and need to update although it does not popolate nor work once the SAN is edited to an existing certificate. Does nayone have any additional info one this.

     

    • Ken_B_50116's avatar
      Ken_B_50116
      Icon for Cirrostratus rankCirrostratus

      My experience has been this: When you click the "renew" button in LTM 11.5.4, the SAN field is blank. You need to paste in all of the SAN names and any new names you are adding in the correct format. This will generate a .csr file which can be presented to your cert provider.

       

      The correct format for the SAN field is:

       

      DNS:name1.domain.com, DNS:name2,domain.com, DNS:fubar.flop.com, DNS:

       

  • I am running 11.5 and need to update although it does not popolate nor work once the SAN is edited to an existing certificate. Does nayone have any additional info one this.

     

    • Ken_B_50116's avatar
      Ken_B_50116
      Icon for Cirrostratus rankCirrostratus

      My experience has been this: When you click the "renew" button in LTM 11.5.4, the SAN field is blank. You need to paste in all of the SAN names and any new names you are adding in the correct format. This will generate a .csr file which can be presented to your cert provider.

       

      The correct format for the SAN field is:

       

      DNS:name1.domain.com, DNS:name2,domain.com, DNS:fubar.flop.com, DNS: