Forum Discussion

UmeshF5's avatar
UmeshF5
Icon for Nimbostratus rankNimbostratus
Dec 03, 2019

Single wild cart cert for all f5 external VIP

Hi,

 

What if we use one wildcard certificate for my all external f5 setup. As we have all our setup belongs to one domain only.

 

Example:- Setup what we have like

 

test.example.com

check,example.com

take.example.com

 

So can we use just one *.example.com certificate for all above setup. Instead of purchasing separate cert for each setup. I think its technically its possible but is it recommended. Just wanted to know best practices and what will be impact if we use one wild card cert for all.

 

1 Reply

  • Hi,

     

    Yes, you can use only one wildcard certificate (*.example.com) for all your virtual servers. You can even have only one virtual server and select the pool you want to forward the traffic to based on the hostname via a LTM policy our via an iRule.

     

    About recommendation, I don't know on my own if there any. The only thing I see here is a higher security risk in case the private key is leaked as all your sub-domains gonna be at risk, but this is quite the extrem :)

     

    One security recommendation I would give you is to set a password on your private key when importing one in F5 certificate store.