aethercert
Load balancers

Automated certificate renewal for F5 BIG-IP

On BIG-IP a renewal means uploading two files, updating two objects and pointing a client-SSL profile at them. The F5 package does this over iControl REST from an agent inside your network.

The deployment steps defined in this package's manifest.

At a glance

Package
f5-bigip-target 2.0.0
Compatibility
BIG-IP >=13.0 <18.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
Session login
Capabilities
Import certificateImport private keyUpdate binding
Deployment steps
uploadCertFile → createCertObject → updateCertObject* → uploadKeyFile → createKeyObject → updateKeyObject* → updateClientSslProfile*
Rollback
None
Key usage
No requirement

* conditional step

What it does

The agent opens an iControl REST session, uploads the certificate and key, and creates or updates the certificate and key objects in the configured partition.

If you name a client-SSL profile, the package points it at the new certificate and key, so virtual servers using that profile serve the renewed certificate.

How it runs

  1. 01

    uploadCertFile / createCertObject / updateCertObject

    The certificate is uploaded and the certificate object created or updated.

  2. 02

    uploadKeyFile / createKeyObject / updateKeyObject

    The key is uploaded and the key object created or updated.

  3. 03

    updateClientSslProfile

    The named client-SSL profile is switched to the new certificate and key, if configured.

What you configure

  • Management host and port
  • Username and password (stored encrypted)
  • Certificate object name and partition (default Common)
  • Optional client-SSL profile

Prerequisites

  • An agent with network access to the BIG-IP management interface
  • A BIG-IP user allowed to manage SSL certificates and profiles in the partition

Limitations

  • Configuration sync across a device group follows your existing BIG-IP sync settings.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

F5 BIG-IP

Which BIG-IP versions are supported?

The package declares BIG-IP 13.0 up to (not including) 18.0.

Do virtual servers need to be changed?

No. Virtual servers keep their client-SSL profile; the profile is pointed at the renewed certificate and key.

Automate F5 BIG-IP

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.