← Integrations

Automated SSL certificate renewal for F5 BIG-IP

F5 BIG-IP won't update a renewed certificate on its own. CertKit will.

A BIG-IP binds a named certificate and key to a Client SSL profile, and your virtual servers reference that profile. When a certificate renews, nothing changes on the device until someone uploads the new certificate, creates the SSL objects, repoints the profile's certificate chain, and saves the running configuration. Every 47 days. On every BIG-IP you manage.

CertKit centralizes certificate issuance and renewal, then pushes the renewed certificate to your BIG-IP devices automatically via the CertKit Agent and the iControl REST API, repoints the Client SSL profile, and saves the config.

Start free trial Watch demo

Built for F5 BIG-IP

A pre-built Client SSL profile template ships in your CertKit account. No scripting required.

CertKit renews your BIG-IP certificate for you. On every renewal it uploads the new certificate and key, creates fresh SSL objects, repoints the Client SSL profile to them, saves the configuration, and removes the old objects. No TMUI clicks, no manual import, no maintenance window to schedule.

A pre-built Client SSL profile template ships with your CertKit account. Point CertKit at your BIG-IP once and it handles every renewal after that. If you want to see or adjust exactly what runs, the full deployment script is right there in your account.

How to install an SSL certificate on F5 BIG-IP

The manual process, if you want to do it yourself:

  1. Get the renewed certificate and key. Generate a CSR under System → Certificate Management → Traffic Certificate Management, or create the CSR and key externally, then submit it to a certificate authority.
  2. Import the certificate and key. In the SSL Certificate List, choose Import and upload the certificate, intermediates, and key. A BIG-IP won't overwrite an object that's bound to a live profile, so the renewed certificate has to come in under a new name.
  3. Repoint the Client SSL profile. Under Local Traffic → Profiles → SSL → Client, edit the profile's Certificate Key Chain to reference the new objects. Every virtual server using the profile picks up the change.
  4. Save and sync. Save the running configuration so the change survives a reboot, then sync to the HA peer.
  5. Clean up. Delete the old certificate and key objects once nothing references them, in the right partition, on every BIG-IP that serves the domain.

Every one of these steps is manual, and the BIG-IP won't repeat any of them for you when the certificate renews. With lifetimes shrinking to 47 days, installation stops being an annual chore and becomes a recurring task: eight times a year, on every profile, on every device. Miss one and a customer can't reach an application.

At 47 days, automated certificate renewal is the only sustainable way to do F5 certificate management. Here's how CertKit does it.

How it works

 Your network            CertKit                 ACME CA
┌───────────────────┐     ┌──────────────────┐    ┌─────────────┐
│  ┌─────────────┐  │     │                  │    │             │
│  │Deploy Agent │◄─┼─────┤  Issue & Renew   │◄──►│             │
│  └──┬────┬─────┘  │     │   Certificates   │    │             │
│     │    │iControl│     │                ┌───┐  └─────────────┘
│     │    │ REST   │     └───────────┬────│DNS│
│     ▼    ▼        │                 │    └───┘
│ ┌──────────────┐  │                 │
│ │ F5 BIG-IP    │  │                 │
│ │ [x] Uploaded │  │ ◄───────────────┘
│ │ [x] Saved    │  │       Verify
│ └──────────────┘  │
└───────────────────┘

CertKit issues and renews certificates centrally in the cloud using delegated DNS validation. You create a one-time CNAME record; CertKit handles every ACME challenge after that.

The deploy agent is a small service you run on a server inside your network. It makes an outbound HTTPS connection to CertKit to pull each renewed certificate, then connects to the BIG-IP over the iControl REST API on your management network to upload the certificate and key, repoint the Client SSL profile, and save. The BIG-IP never talks to CertKit or the public internet directly, never runs ACME, needs no port 80 open, and never stores DNS credentials. One deploy agent can reach every BIG-IP and other appliance on that network, so there's nothing to install on the load balancers themselves.

Using CertKit to manage our public-facing SSL certificates has been an excellent decision. The platform is user-friendly, certificates are easy to deploy, and the automation agent streamlines the entire certificate lifecycle, eliminating concerns around shortening certificate validity periods.

Chris Austin, IT Engineer, Buckman

What CertKit handles

Setup takes about ten minutes

  1. Connect your domain. Add a one-time CNAME record to delegate DNS validation to CertKit. Every renewal challenge after that is automatic.
  2. Create a BIG-IP management account. A scoped administrator account that can upload SSL files, edit Client SSL profiles, and save the configuration over iControl REST.
  3. Install the CertKit Agent. One command on any Windows or Linux host with HTTPS reachability to the BIG-IP management interface. The agent runs as a background service and needs no inbound firewall rules.
  4. Add the F5 deployment script. The pre-built Client SSL profile template is in your account. Set your BIG-IP hostname, partition, profile name, and credentials. CertKit runs it on every renewal.

See the full architecture →

Why not script iControl REST yourself?

The iControl REST flow has sharp edges: chunked file uploads with byte ranges, separate ssl-cert and ssl-key object creation, the in-use lock that blocks overwriting a bound certificate, partition-qualified object names, and a config save that has to land before an HA peer syncs. We built and tested the deployment so you don't have to. CertKit issues the certificate via delegated DNS validation, then the agent handles the upload, the profile repoint, the save, and the cleanup as one verified step, with no ACME client on the load balancer.

F5 is just one part of your network edge

Most networks have more than one place where TLS certificates live: other load balancers like Citrix NetScaler, VPN concentrators, web servers, the Kubernetes ingresses behind the virtual servers, and firewall vendors like Palo Alto, Fortinet, and SonicWall. CertKit automates all of it from one account.

See all integrations

Start automating F5 BIG-IP certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing