6.5.9 F5 BIG-IP
Upload certificate material and update the intended client SSL profile
CertKit provides Windows and Linux F5 BIG-IP (REST API) templates. Both upload the certificate and private key through iControl REST, update an existing client SSL profile, save the running configuration, and remove superseded CertKit uploads.
Requirements
- The agent host must reach the BIG-IP management interface over HTTPS.
- The BIG-IP account must be allowed to upload SSL certificate and key files, modify client SSL profiles, and save configuration.
- The target client SSL profile must already exist.
- Use the administrative partition containing that profile. The default is
Common.
The template tolerates a self-signed certificate on the BIG-IP management interface.
Template settings
| Setting | Requirement |
|---|---|
| F5 management IP/host and port | Management address, including a non-standard port such as 10.1.2.3:8443. |
| F5 username/password | Account with SSL file and client SSL profile permissions. |
| F5 partition | Partition containing the profile; commonly Common. |
| SSL Client profile name | Existing client-ssl profile that should use the renewal. |
Common problems
- Profile not found: confirm both the profile name and administrative partition. A profile in another partition is not found by name alone.
- Authorization failure: confirm the account can manage SSL files and profiles, not only view them.
- Certificate imported but traffic is unchanged: confirm the deployment targets the client SSL profile bound to the active virtual server.
- Management connection failure: include the management port when it is not 443 and confirm network access from the agent host.
The template uses timestamped object names internally and cleans up its own superseded objects. It does not remove certificates or keys that were not created by CertKit.
For a product overview, see certificate automation for F5 BIG-IP.