Forum Discussion

hidehara_189502's avatar
hidehara_189502
Icon for Nimbostratus rankNimbostratus
Apr 12, 2018

Is ca-bundle.crt updated when I update BIG-IP ?

I compared ca-bundle.crt on BIG-IP between 11.5.x and 12.1.x. Cause of a problem of client certification auth I faced.

 

What I found difference is that is following:

 

BIG-IP 12.1.x (VE) :

 

  • 7108135 2017-04-29 20:18 /config/ssl/ssl.crt/ca-bundle.crt

BIG-IP 11.5.x (appliance):

 

  • 3635692 Jan 16 2016 /config/ssl/ssl.crt/ca-bundle.crt

When I update 11.5.x to 12.1.x , the ca-bundle.crt will be replaced newer one ? OR Should I copy the ca-bundle.crt from 12.1.x to 11.5.x?

 

I need correct GlobalSign Root CA, but a ca-bundle.crt on 11.5.x has duplicated CA inside ( same subject key they have ). Also number of GlobalSign CA on 12.1.x is 9. That is more than 3 on 11.5.x.

 

Thanks for reading.