F5 BIG-IP
Manages certificates in F5 BIG-IP SSL profiles (Client SSL and Server SSL). Created automatically via F5 Discovery.
How it's created
F5 Stores are automatically provisioned during Discovery when the Create Stores automatically option is enabled. Each Client SSL and Server SSL profile found becomes a Store in the CLM.
Store details
| Card | Description |
|---|---|
| Total | Total certificates in the SSL profile |
| Expiring | Certificates nearing expiration |
F5 BIG-IP Integration Section (Read-only) — displays the data collected during discovery: F5 integration, BIG-IP host, linked agent, and profile type (Client SSL or Server SSL). To change the host or credentials, edit the source integration in Integrations → F5 BIG-IP.
SSL Profile on F5 Section (Read-only) — displays partition, profile name, cert name, key name, and chain name.
Certificate Chain (Bundle) — editable toggle:
- Active: the deploy sends the intermediate CA chain to F5 and links it to the profile
- Inactive: the profile is written with
chain: noneand only the leaf certificate is presented during the TLS handshake
Current Certificate — displays common name, issuer, validity, and thumbprint of the certificate currently installed on the profile.
Linked Virtual Servers — lists the Virtual Servers that reference this SSL profile on F5.
Installed Certificates — lists all certificates installed on the store with issuer, issuance date, validity, bind status, and the result of the last deploy. Click View history to see the full log of past deploys.
Install a certificate
On the details screen, click Install Certificate, select the certificate from the inventory, and confirm. The CLM performs the deploy to the SSL profile via the linked agent.