Skip to main content

F5 BIG-IP

Connects the CLM to F5 BIG-IP via iControl REST for discovery and deployment of certificates in SSL profiles.


Uses of this integration

FeatureSupported
Discovery of SSL profiles (Client SSL, Server SSL)
Deploy of certificates to SSL profiles
Cleanup of old certificates after renewal
Certificate issuance

Prerequisites

Linux CLM Agent installed and online with network access to F5 BIG-IP. The agent is what makes the iControl REST calls to BIG-IP — the CLM never connects directly.

User on F5 with the following minimum permissions:

PermissionPurpose
Certificate Manager (role)Manage certificates and keys on BIG-IP
Access to the target partitionRead and write on the partition's SSL profiles
Linux Agent required
See the [Install the Agent — Linux](/guias/agente/linux) guide to install and configure the agent before registering this integration.

Register

  1. Go to Integrations in the sidebar menu
  2. Find the BigIP-F5 card and click + Configure
  3. Fill in the fields:
FieldDescription
NameName to identify the integration, e.g. BigIP-F5-Production
Host (BIG-IP)IP or hostname of the BIG-IP, e.g. 10.66.33.93
PortiControl REST API port (default: 8443)
UserUser with certificate management permission
PasswordLeave blank to keep the current password when editing
Linux AgentAgent that will make the calls to the BIG-IP API
Allow self-signed certificatesEnable if BIG-IP uses internal TLS with a self-signed certificate
  1. Click Test connection to validate and then Update

Edit

Click the menu on the integration card and select Edit. Leave the password blank to keep it unchanged.


Delete

Remove the linked Stores and discovery jobs before deleting the integration.