{"id":1031,"date":"2016-10-12T20:00:00","date_gmt":"2016-10-12T20:00:00","guid":{"rendered":"https:\/\/fir3netwp.gmsrrpobkbd.com\/2016\/10\/12\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type\/"},"modified":"2023-02-24T12:59:43","modified_gmt":"2023-02-24T12:59:43","slug":"f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type","status":"publish","type":"post","link":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html","title":{"rendered":"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type"},"content":{"rendered":"

Issue<\/h2>\n

Starting in BIG-IP 11.5.0, you can associate multiple SSL certificate\/key pair types with a single SSL profile. This configuration allows the virtual server to accept SSL connections from clients supporting newer cryptographic algorithms (such as ECC), while continuing to accept connections from clients supporting traditional algorithms[1]<\/sup>.<\/p>\n

However, with this new feature you are cannot associate multiple certificate\/key pairs of the same type within profile. If certificate\/key pairs of the same type are assigned to the same SSL Profile this will result in the F5 being unable to load the configuration, and the following error message being returned,<\/p>\n

Client SSL profile cannot contain more than one set of same certificate\/key type<\/pre>\n

Solution<\/h2>\n

To resolve the issue remove the additionally cert\/key pair from the SSL Profile, like so,<\/p>\n

ltm profile client-ssl \/Common\/fir3net.com-2016 {\r\n    app-service none\r\n    cert-key-chain {\r\n-       default {\r\n-           cert \/Common\/default.crt\r\n-           key \/Common\/default.key\r\n-       }\r\n        fir3net.com-certkey {\r\n            cert \/Common\/fir3net.com-2016.crt\r\n            chain \/Common\/VeriSignClass3-InternationalServerCA-G3.crt\r\n            key \/Common\/fir3net.com-2016.key\r\n        }\r\n    }\r\n    defaults-from \/Common\/clientssl\r\n}<\/pre>\n

To validate the configuration against this issue the following command can be used, from with TMSH. This is recommended prior to performing any upgrades from v11.5.x.<\/p>\n

load sys config verify<\/pre>\n

References<\/h2>\n

[1] https:\/\/support.f5.com\/kb\/en-us\/solutions\/public\/15000\/000\/sol15062.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"

Issue Starting in BIG-IP 11.5.0, you can associate multiple SSL certificate\/key pair types with a single SSL profile. This configuration allows the virtual server to accept SSL connections from clients supporting newer cryptographic algorithms (such as ECC), while continuing to accept connections from clients supporting traditional algorithms[1]. However, with this new feature you are cannot … Read more<\/a><\/p>\n","protected":false},"author":2,"featured_media":857,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[],"yoast_head":"\nF5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type<\/title>\n<meta name=\"description\" content=\"Issue Starting in BIG-IP 11.5.0, you can associate multiple SSL certificate\/key pair types with a single SSL profile. This configuration allows the\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type\" \/>\n<meta property=\"og:description\" content=\"Issue Starting in BIG-IP 11.5.0, you can associate multiple SSL certificate\/key pair types with a single SSL profile. This configuration allows the\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html\" \/>\n<meta property=\"og:site_name\" content=\"Fir3net\" \/>\n<meta property=\"article:published_time\" content=\"2016-10-12T20:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-24T12:59:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png\" \/>\n\t<meta property=\"og:image:width\" content=\"266\" \/>\n\t<meta property=\"og:image:height\" content=\"297\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Rick Donato\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Rick Donato\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html\"},\"author\":{\"name\":\"Rick Donato\",\"@id\":\"https:\/\/www.fir3net.com\/#\/schema\/person\/ab35009601b7687ee1c5310be6038037\"},\"headline\":\"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type\",\"datePublished\":\"2016-10-12T20:00:00+00:00\",\"dateModified\":\"2023-02-24T12:59:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html\"},\"wordCount\":171,\"publisher\":{\"@id\":\"https:\/\/www.fir3net.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png\",\"articleSection\":[\"F5 Loadbalancers\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html\",\"url\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html\",\"name\":\"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type\",\"isPartOf\":{\"@id\":\"https:\/\/www.fir3net.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png\",\"datePublished\":\"2016-10-12T20:00:00+00:00\",\"dateModified\":\"2023-02-24T12:59:43+00:00\",\"description\":\"Issue Starting in BIG-IP 11.5.0, you can associate multiple SSL certificate\/key pair types with a single SSL profile. This configuration allows the\",\"breadcrumb\":{\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#primaryimage\",\"url\":\"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png\",\"contentUrl\":\"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png\",\"width\":266,\"height\":297},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.fir3net.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Networking\",\"item\":\"https:\/\/www.fir3net.com\/networking\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Loadbalancers\",\"item\":\"https:\/\/www.fir3net.com\/networking\/loadbalancers\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"F5 Loadbalancers\",\"item\":\"https:\/\/www.fir3net.com\/networking\/loadbalancers\/f5-big-ip\"},{\"@type\":\"ListItem\",\"position\":5,\"name\":\"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.fir3net.com\/#website\",\"url\":\"https:\/\/www.fir3net.com\/\",\"name\":\"Fir3net\",\"description\":\"Keeping you in the know\",\"publisher\":{\"@id\":\"https:\/\/www.fir3net.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.fir3net.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.fir3net.com\/#organization\",\"name\":\"Fir3net\",\"url\":\"https:\/\/www.fir3net.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.fir3net.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.fir3net.com\/wp-content\/uploads\/Fir3net-Background-Logo-compressed.png\",\"contentUrl\":\"https:\/\/www.fir3net.com\/wp-content\/uploads\/Fir3net-Background-Logo-compressed.png\",\"width\":390,\"height\":88,\"caption\":\"Fir3net\"},\"image\":{\"@id\":\"https:\/\/www.fir3net.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.fir3net.com\/#\/schema\/person\/ab35009601b7687ee1c5310be6038037\",\"name\":\"Rick Donato\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.fir3net.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d75d69a54c0ca3b32c24c3a9703b623c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d75d69a54c0ca3b32c24c3a9703b623c?s=96&d=mm&r=g\",\"caption\":\"Rick Donato\"},\"description\":\"Rick Donato is a Network Automation Architect\/Evangelist and the founder of Packet Coders.\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type","description":"Issue Starting in BIG-IP 11.5.0, you can associate multiple SSL certificate\/key pair types with a single SSL profile. This configuration allows the","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html","og_locale":"en_US","og_type":"article","og_title":"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type","og_description":"Issue Starting in BIG-IP 11.5.0, you can associate multiple SSL certificate\/key pair types with a single SSL profile. This configuration allows the","og_url":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html","og_site_name":"Fir3net","article_published_time":"2016-10-12T20:00:00+00:00","article_modified_time":"2023-02-24T12:59:43+00:00","og_image":[{"width":266,"height":297,"url":"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png","type":"image\/jpeg"}],"author":"Rick Donato","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Rick Donato","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#article","isPartOf":{"@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html"},"author":{"name":"Rick Donato","@id":"https:\/\/www.fir3net.com\/#\/schema\/person\/ab35009601b7687ee1c5310be6038037"},"headline":"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type","datePublished":"2016-10-12T20:00:00+00:00","dateModified":"2023-02-24T12:59:43+00:00","mainEntityOfPage":{"@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html"},"wordCount":171,"publisher":{"@id":"https:\/\/www.fir3net.com\/#organization"},"image":{"@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#primaryimage"},"thumbnailUrl":"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png","articleSection":["F5 Loadbalancers"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html","url":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html","name":"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type","isPartOf":{"@id":"https:\/\/www.fir3net.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#primaryimage"},"image":{"@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#primaryimage"},"thumbnailUrl":"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png","datePublished":"2016-10-12T20:00:00+00:00","dateModified":"2023-02-24T12:59:43+00:00","description":"Issue Starting in BIG-IP 11.5.0, you can associate multiple SSL certificate\/key pair types with a single SSL profile. This configuration allows the","breadcrumb":{"@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#primaryimage","url":"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png","contentUrl":"https:\/\/www.fir3net.com\/wp-content\/uploads\/2014\/09\/images_articles_certificate.png","width":266,"height":297},{"@type":"BreadcrumbList","@id":"https:\/\/www.fir3net.com\/Loadbalancers\/F5-BIG-IP\/f5-11-5-x-client-ssl-profile-cannot-contain-more-than-one-set-of-same-certificate-key-type.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.fir3net.com\/"},{"@type":"ListItem","position":2,"name":"Networking","item":"https:\/\/www.fir3net.com\/networking"},{"@type":"ListItem","position":3,"name":"Loadbalancers","item":"https:\/\/www.fir3net.com\/networking\/loadbalancers"},{"@type":"ListItem","position":4,"name":"F5 Loadbalancers","item":"https:\/\/www.fir3net.com\/networking\/loadbalancers\/f5-big-ip"},{"@type":"ListItem","position":5,"name":"F5 11.5.x: Client SSL profile cannot contain more than one set of same certificate\/key type"}]},{"@type":"WebSite","@id":"https:\/\/www.fir3net.com\/#website","url":"https:\/\/www.fir3net.com\/","name":"Fir3net","description":"Keeping you in the know","publisher":{"@id":"https:\/\/www.fir3net.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.fir3net.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.fir3net.com\/#organization","name":"Fir3net","url":"https:\/\/www.fir3net.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fir3net.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.fir3net.com\/wp-content\/uploads\/Fir3net-Background-Logo-compressed.png","contentUrl":"https:\/\/www.fir3net.com\/wp-content\/uploads\/Fir3net-Background-Logo-compressed.png","width":390,"height":88,"caption":"Fir3net"},"image":{"@id":"https:\/\/www.fir3net.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.fir3net.com\/#\/schema\/person\/ab35009601b7687ee1c5310be6038037","name":"Rick Donato","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fir3net.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d75d69a54c0ca3b32c24c3a9703b623c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d75d69a54c0ca3b32c24c3a9703b623c?s=96&d=mm&r=g","caption":"Rick Donato"},"description":"Rick Donato is a Network Automation Architect\/Evangelist and the founder of Packet Coders."}]}},"_links":{"self":[{"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/posts\/1031"}],"collection":[{"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/comments?post=1031"}],"version-history":[{"count":2,"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/posts\/1031\/revisions"}],"predecessor-version":[{"id":3390,"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/posts\/1031\/revisions\/3390"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/media\/857"}],"wp:attachment":[{"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/media?parent=1031"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/categories?post=1031"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fir3net.com\/wp-json\/wp\/v2\/tags?post=1031"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}