Automated certificate renewal for F5 BIG-IP
On BIG-IP a renewal means uploading two files, updating two objects and pointing a client-SSL profile at them. The F5 package does this over iControl REST from an agent inside your network.
package f5-bigip-target 2.0.0
uploadCertFilecreateCertObjectupdateCertObjectwhen configureduploadKeyFilecreateKeyObjectupdateKeyObjectwhen configuredupdateClientSslProfilewhen configured
At a glance
- Package
f5-bigip-target 2.0.0- Compatibility
BIG-IP >=13.0 <18.0- Runs from
- Any Windows or Linux agent with network access to it
- Mechanism
- REST API
- Authentication
- Session login
- Capabilities
- Import certificateImport private keyUpdate binding
- Deployment steps
- uploadCertFile → createCertObject → updateCertObject* → uploadKeyFile → createKeyObject → updateKeyObject* → updateClientSslProfile*
- Rollback
- None
- Key usage
- No requirement
* conditional step
What it does
The agent opens an iControl REST session, uploads the certificate and key, and creates or updates the certificate and key objects in the configured partition.
If you name a client-SSL profile, the package points it at the new certificate and key, so virtual servers using that profile serve the renewed certificate.
How it runs
- 01
uploadCertFile / createCertObject / updateCertObject
The certificate is uploaded and the certificate object created or updated.
- 02
uploadKeyFile / createKeyObject / updateKeyObject
The key is uploaded and the key object created or updated.
- 03
updateClientSslProfile
The named client-SSL profile is switched to the new certificate and key, if configured.
What you configure
- Management host and port
- Username and password (stored encrypted)
- Certificate object name and partition (default Common)
- Optional client-SSL profile
Prerequisites
- An agent with network access to the BIG-IP management interface
- A BIG-IP user allowed to manage SSL certificates and profiles in the partition
Limitations
- Configuration sync across a device group follows your existing BIG-IP sync settings.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Load balancers
Documentation
Frequently asked questions
F5 BIG-IP
Which BIG-IP versions are supported?
The package declares BIG-IP 13.0 up to (not including) 18.0.
Do virtual servers need to be changed?
No. Virtual servers keep their client-SSL profile; the profile is pointed at the renewed certificate and key.
Automate F5 BIG-IP
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.