SSL Certificate Support: Creating a Certificate Signing Request (CSR)

Creating a CSR for F5 Big-IP

» Go back and choose a different server

» What to do after you submit your CSR to Trustwave

» SSL Certificate Purchasing Information for F5 Big-IP

» SSL Certificate installation instructions for F5 Big-IP

Save your previous configuration Save your previous configuration
If you currently have an SSL certificate installed on the Big-IP for a certain host, and you want to put a new SSL certificate on that host, we recommend backing up the entire configuration in the event that there is an issue later on.

To backup your current configuration, run the following command as the root user:

# bigpipe config save yourwebsite.com-backup10-03-2005

The backed up configuration should be in the /usr/local/ucs/Setup_backup.ucs file. Save that file to another location outside of the Big-IP so that you can restore it if necessary. Also, copy your key, csr, and crt files in /config/bigconfig/ so that they end with .backup. After you have copied them to their new names you should remove them from the folder to make room for the new csr, key, and crt.

Create a new SSL configuration Create a new SSL configuration
Before creating the new CSR and key, you will need to create a new SSL configuration file by running the following command:

# /usr/local/bin/genconf

When you run this command, the Big-IP will ask for your company information. When you enter that information, please keep a few things in mind:

Country/State/City - Enter the locality information based on where your business operates, not where your server is located. Spell out all state and city information. For example, if your business operates in Texas, use "Texas" for the state, rather than "TX". If you are an international customer in a country without states or provinces, please use your country name in the state field.

Organization - Please use your full, unabbreviated legal business name including any applicable suffix, such as "Inc" or "LLC". If your company name is registered in an abbreviated form, then you may use abbreviations if you would like to do so.

Common Name - This is where you type the web address of your site. For example, www.securetrust.com and xramp.com are both acceptable. Please do not include http:// or https://. When ordering a Wildcard SSL Certificates use *.Trustwave.com

Generate the Key and CSR Generate the Key and CSR
Run the following command to generate a new certificate request:

# /usr/local/bin/genkey www.yourdomain.com

Be sure to replace www.yourdomain.com with the actual hostname of your host. You will be prompted again for your company information during this step.

Submit the CSR to Trustwave Submit the CSR to Trustwave
After the genkey command is complete, you will have a CSR in the file /config/bigconfig/ssl.csr/www.yourdomain.com.csr. Move that file to a computer that can access the Trustwave Control Center (we recommend using FTP to move the file). From there, you can open your CSR in a suitable text editor and submit it within the Trustwave Control Center.

» After you submit your CSR, check your validation status

Trustwave Technical Support Options
Toll-Free: 866-775-2378
Direct: +1-608-294-6940
E-Mail: sslsupport@trustwave.com
SSL Certificate Customers - Instant Support!
We invite our SSL Certificate Customers to use our new online troubleshooter, HelpNow, to diagnose SSL certificate issues instantly. Get HelpNow! »
Trustwave Support Tips:
If you are contacting us about your SSL certificate via e-mail, please provide us with your website's address and a detailed description of the issue. Screenshots may also help us resolve your problem quickly, so you are welcome to include those as well.
Home Legal Information Privacy Policy Contact Us International
© Trustwave
Ph: 888-878-7817 (312-873-7500 outside U.S. or Canada) Fax: 312-443-8028 info@trustwave.com