F5 BIG-IP
Connects the CLM to F5 BIG-IP via iControl REST for discovery and deployment of certificates in SSL profiles.
Uses of this integration
| Feature | Supported |
|---|---|
| Discovery of SSL profiles (Client SSL, Server SSL) | ✅ |
| Deploy of certificates to SSL profiles | ✅ |
| Cleanup of old certificates after renewal | ✅ |
| Certificate issuance | ❌ |
Prerequisites
Linux CLM Agent installed and online with network access to F5 BIG-IP. The agent is what makes the iControl REST calls to BIG-IP — the CLM never connects directly.
User on F5 with the following minimum permissions:
| Permission | Purpose |
|---|---|
Certificate Manager (role) | Manage certificates and keys on BIG-IP |
| Access to the target partition | Read and write on the partition's SSL profiles |
Linux Agent required
See the [Install the Agent — Linux](/guias/agente/linux) guide to install and configure the agent before registering this integration.
Register
- Go to Integrations in the sidebar menu
- Find the BigIP-F5 card and click + Configure
- Fill in the fields:
| Field | Description |
|---|---|
| Name | Name to identify the integration, e.g. BigIP-F5-Production |
| Host (BIG-IP) | IP or hostname of the BIG-IP, e.g. 10.66.33.93 |
| Port | iControl REST API port (default: 8443) |
| User | User with certificate management permission |
| Password | Leave blank to keep the current password when editing |
| Linux Agent | Agent that will make the calls to the BIG-IP API |
| Allow self-signed certificates | Enable if BIG-IP uses internal TLS with a self-signed certificate |
- Click Test connection to validate and then Update
Edit
Click the ⋮ menu on the integration card and select Edit. Leave the password blank to keep it unchanged.
Delete
Remove the linked Stores and discovery jobs before deleting the integration.