Migrate the SSL configuration to the enhanced SSL profile
-
Front-end profile: Applies to the entities that receive requests from a client.
-
Back-end profile: Applies to entities that send client requests to the back-end server.
Problem statement
Solution
-
Save the configuration.
-
Run the script.
-
Review the output file.
-
Enable the default profile.
-
Batch the file.
save config. Also, ensure that the default profile is enabled before you batch the file. For a large configuration, running the script can take up to 30 minutes.
To migrate the SSL configuration by using the NetScaler GUI
-
Navigate to System > Diagnostics. Under Maintenance, click Save configuration.
-
Navigate to Traffic Management > SSL > Tools > SSL Profile Converter.
-
Click Run SSL Profile Conversion.
-
Click View File to review the output file. Click Download File to download the output file and review offline.
-
Go back to the SSL page. Under Settings, click Change advanced SSL settings.
-
In the Change Advanced SSL settings page, select Enable Default Profile.
-
Navigate to System > Diagnostics. Under Utilities, click Batch configuration.
-
Provide the File Path and click Run.
Result
/nsconfig/partitions/<partition_name>/sslprofile_cmds.txt.
/nsconfig/sslprofile_cmds.txt.
To migrate the SSL configuration by using the NetScaler CLI
save config
convert SSL defaultprofile