Skip to main content

F5 BIG-IP

Manages certificates in F5 BIG-IP SSL profiles (Client SSL and Server SSL). Created automatically via F5 Discovery.


How it's created

F5 Stores are automatically provisioned during Discovery when the Create Stores automatically option is enabled. Each Client SSL and Server SSL profile found becomes a Store in the CLM.


Store details

CardDescription
TotalTotal certificates in the SSL profile
ExpiringCertificates nearing expiration

F5 BIG-IP Integration Section (Read-only) — displays the data collected during discovery: F5 integration, BIG-IP host, linked agent, and profile type (Client SSL or Server SSL). To change the host or credentials, edit the source integration in Integrations → F5 BIG-IP.

SSL Profile on F5 Section (Read-only) — displays partition, profile name, cert name, key name, and chain name.

Certificate Chain (Bundle) — editable toggle:

  • Active: the deploy sends the intermediate CA chain to F5 and links it to the profile
  • Inactive: the profile is written with chain: none and only the leaf certificate is presented during the TLS handshake

Current Certificate — displays common name, issuer, validity, and thumbprint of the certificate currently installed on the profile.

Linked Virtual Servers — lists the Virtual Servers that reference this SSL profile on F5.

Installed Certificates — lists all certificates installed on the store with issuer, issuance date, validity, bind status, and the result of the last deploy. Click View history to see the full log of past deploys.


Install a certificate

On the details screen, click Install Certificate, select the certificate from the inventory, and confirm. The CLM performs the deploy to the SSL profile via the linked agent.