SSL Installation: F5 Big-IP Load Balancer v8 (or earlier)

March 25, 2019

SSL Installation: F5 Big-IP Load Balancer v8 or earlier

The following instructions will guide you through the SSL installation process on F5 Big-IP Load Balancer V8 or Earlier.

If you have more than one server or device, you will need to install the certificate on each server or device you need to secure.

  • Make sure you have all the following files saved before proceeding:

Your Server Certificate
This is the certificate you received from the CA for your domain. You may have been sent this via email. If not, you can download it by visiting your Account Dashboard and clicking on your order.

Intermediate Certificates
These files allow the devices connecting to your server to identify the issuing CA. There may be more than one of these certificates. If you got your certificate in a ZIP folder, it should also contain the Intermediate certificate(s), which is sometimes referred to as a CA Bundle.

Your Private Key
This file should be on your server, or in your possession if you generated your CSR from a free generator tool. On certain platforms, such as Microsoft IIS, the private key is not immediately visible to you but the server is keeping track of it.

  1. Transfer your server and intermediate certificates on to the Big-IP device via FTP.
  2. Rename your server certificate, replacing any underscores with periods.
  3. Copy your server certificate to: /config/bigconfig/ssl.crt/folder
  4. Copy your intermediate certificate to: /config/bigconfig/ssl.crt/folder
  5. Restart your proxy using the following command:

# bigpipe proxy <IP Address>:443 disable
# bagpipe proxy :443 enable

Congratulations! You've successfully installed your SSL certificate!

To check your work, visit the website in your browser at https://yourdomain.tld and view the certificate/site information to see if HTTPS/SSL is working properly.
Remember, you may need to restart your server for changes to take effect.