Import and convert SSL files
-
For certificate files: /nsconfig/ssl/certfile
-
For private keys: the /nsconfig/ssl/keyfile
-
For CRLs: /var/netscaler/ssl/crlfile
-
For DH keys: /nsconfig/ssl/dhfile
Import a certificate file
Import a certificate file from a remote host by using the CLI
import ssl certFile [<name>] [<src>]
import ssl certfile my-certfile http://www.example.com/file_1show ssl certfile
Name : my-certfile
URL : http://www.example.com/file_1
rm ssl certFile command, which accepts only the 'name' argument.
Import a key file from a remote host by using the CLI
import ssl keyFile [<name>] [<src>]
import ssl keyfile my-keyfile http://www.example.com/key_fileshow ssl keyfile
Name : my-keyfile
URL : http://www.example.com/key_file
rm ssl keyFile command, which accepts only the 'name' argument.
Import a CRL file from a remote host by using the CLI
import ssl crlFile [<name>] [<src>]
rm ssl crlFile command, which accepts only the \<name\> argument.
import ssl crlfile my-crlfile http://www.example.com/crl_file
show ssl crlfile
Name : my-crlfile
URL : http://www.example.com/crl_file
Import a DH file from a remote host by using the CLI
import ssl dhFile [<name>] [<src>]
import ssl dhfile my-dhfile http://www.example.com/dh_file
show ssl dhfile
Name : my-dhfile
URL : http://www.example.com/dh_file
rm ssl dhFile command, which accepts only the \<name\> argument.
Import an SSL resource by using the GUI
Import PKCS#8 and PKCS#12 certificates
-----BEGIN ENCRYPTED PRIVATE KEY-----
leuSSZQZKgrgUQ==
-----END ENCRYPTED PRIVATE KEY-----
Open the OpenSSL interface from the CLI
-
Open an SSH connection to the appliance by using an SSH client, such as PuTTY.
-
Log on to the appliance by using the administrator credentials.
-
At the command prompt, type shell.
-
At the shell prompt type
openssl.
Open the OpenSSL interface from the GUI
Convert a non-supported PKCS#8 key format to an encrypted supported key format by using the OpenSSL interface
OpenSSL>rsa- in <PKCS#8 Key Filename> -des3 -out <encrypted Key Filename>
OpenSSL>ec -in <PKCS#8 Key Filename> -des3 -out <encrypted Key Filename>
Parameters for converting an unsupported key format to a supported key format
-
PKCS#8 Key Filename: The input file name of the incompatible PKCS#8 private key.
-
encrypted Key Filename: The output file name of the compatible encrypted private key in PEM format.
-
unencrypted Key Filename: The output file name of the compatible unencrypted private key in PEM format.
Convert SSL certificates for import or export
Convert the format of a certificate by using the CLI
convert ssl pkcs12 <outfile> [-import [-pkcs12File <inputFilename>] [-des | -des3] [-export [-certFile <inputFilename>] [-keyFile <inputFilename>]]
convert ssl pkcs12 Cert-Import-1.pem -import -pkcs12File Cert-Import-1.pfx -des
convert ssl pkcs12 Cert-Client-1.pfx -export -certFile Cert-Client-1 -keyFile Key-Client-1
Convert the format of a certificate by using the GUI
-
Navigate to Traffic Management > SSL and, in the Tools group, select Import PKCS#12.Import PKCS#12
-
Specify the PEM certificate name in the Output File Name field.
-
Browse to the location of the PFX certificate on your local computer or the appliance.Browse to PFX certificate
-
Click OK.
-
Click Manage Certificates / Keys / CSRs to view the converted PEM file.View converted PEM file
-
You can view the uploaded PFX file and the converted PEM file.View files
-
Navigate to SSL > Certificates > Server Certificates and click Install.
-
Specify a Certificate-Key Pair Name.
-
Browse to the location of the PEM file.
-
Specify the password when prompted.
-
Click Install.Install server certificate
-
Bind the certificate-key pair to an SSL virtual server.