Generate a CSR: F5 BIG IP

To generate a Certificate Signing Request (CSR), please do the following:

You must create an SSL configuration file, before generating a CSR. This can be completed by running the following command:

# /usr/local/bin/genconf

When you run this command, the Big-IP will ask for your company information:

  • Country Name (2 letter code) [AU]:
  • State or Province Name (full name) [Some-State]:
  • Locality Name (eg, city) []:
  • Organization Name (eg, company) []:
  • Organizational Unit Name (eg, section) []:
  • Common Name (eg, YOUR name) []: (Must be the Fully Qualifed Domain Name)
  • Email Address - Leave blank
  • Challenge Password - Leave blank
  • Retype Password - Leave blank

Run the following command to generate a new certificate request:

# /usr/local/bin/genkey www.yourdomain.com

Be sure to replace www.yourdomain.com with your Common name – FQDN (Fully Qualifed domain name).

You will be prompted again for your company information during this step:

  • Country Name (2 letter code) [AU]:
  • State or Province Name (full name) [Some-State]:
  • Locality Name (eg, city) []:
  • Organization Name (eg, company) []:
  • Organizational Unit Name (eg, section) []:
  • Common Name (eg, YOUR name) []: (Must be the FQDN - Fully Qualifed Domain Name)

The CSR will be stored in the following:

/config/bigconfig/ssl.crt/Fully Qualified Domain Name.crt

Copy the entire contents of the CSR, insuring to include:

-----BEGIN CERTIFICATE REQUEST-----

and

-----END CERTIFICATE REQUEST-------

Offer

Answer options

Your feedback was successfully added.

Answer tracking

Track

Watch the content of this article for changes.