Forum Discussion

Tony_Jarvis_132's avatar
Tony_Jarvis_132
Icon for Altostratus rankAltostratus
Jun 24, 2014

SSL certificates - need to export from current servers?

Hi all

 

Apologies for the noob question, since this is my first time working with SSL certificates. We have a server team who went through the process of creating the SSL certificate request, and then the CA emailed them the certificate installation instructions. They then proceeded to install the certificate on their servers and all is fine.

 

The challenge now is that we are going to do the SSL offloading on the F5 instead of their servers. The server team have forwarded me the email they received from the CA with the certificate installation instructions. My question is as follows:

 

  • Can I simply take the email and included certificates from the CA and install onto the F5, or
  • Must I instead ask the server team to do some sort of certificate export from their servers, and then import this certificate onto the F5 instead of using the certificates that were emailed initially from the CA?

I hope that makes sense. Please do let me know if any additional details are required.

 

3 Replies

  • As long as you have the cert and key you should be able to import it.

     

    -=Bhattman=-

     

  • It's not the passphrase - but it's used to general the encrypted keyfile. If the server team has it then you have part of it.

     

    -=Bhattman=-

     

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    The email from the CA won't include the key. This is generated on the server that did the original CSR.

     

    I'd ask the server team to export the certificate from the server and include the key. Then import onto the f5.

     

    N