Create LTM SSL Profile and Enroll Certificate
To trigger this workflow:
-
From the Certificate Lifecycle
Automation catalog, under the Enrollment category, hover your mouse
over the Create LTM SSL Profile and Enroll Certificateworkflow and click
.
The workflow execution page is displayed with the workflow inputs requested at the first stage. -
Under the CA Details section, select the requested field information as
described in the table below.

Table 1. Field descriptions in the CA Details section Field Description *Certificate Group Select the Certificate Group from the options available in the dropdown. *Certificate Authority Select the Certificate Authority from the available options: - DigiCert
- Entrust
- EJBCA
- Microsoft Enterprise
- AppViewX
Note: The Certificate Authority field is populated based on the selected Certificate Group.*CA Account Select the CA Account from the options available in the dropdown. Note: The CA Account field is populated based on the selected Certificate Authority.*Division Select the Division from the options available in the dropdown. Note: This field is displayed only when Digicert is selected as the CA.*Cert Type Select the Cert Type from the options available in the dropdown. Note: This field is displayed only when Digicert or Entrust are selected as the CA.*Input Method Select the required Input Method. The options available are: - Manual: (Default) If you select the Input Method as Manual,
the CSR parameters will have to be entered/selected manually.
For instructions, click here.
- Policy Based: If you select the Input Method as Policy
Based, the CSR parameters fields will be auto-populated based on the policy
associated with the selected Certificate Group.
For instructions, click here.
- Upload CSR: If you select the Input Method as Upload CSR,
you can upload the CSR file to fetch the CSR parameters.
For instructions, click here.
All asterisk (*) marked fields are mandatory.
Enrolling Certificates Based on Input Method
Manual
-
Under the CSR Parameters section, enter or select the requested field
information as described in the table below.
Table 2. Field description for CSR Parameters section Field Description *Common Name Enter the Fully Qualified Domain Name (FQDN) of the server for which certificate is requested. Subject Alternative Name Select the SAN as either: - DNS
- IP Address
DNS Enter a valid DNS if you select the DNS option in the SAN field. Note: This field is displayed if DNS is selected in the The email id of the logged in user is populated automatically. field.IP Address Enter a valid IP Address if you select the IP Address option in the SAN field. Note: This field is displayed if IP Address is selected in the Subject Alternative Name field.Organization Unit Enter the name of the organization unit with which the certificate will be associated. Locality Enter the name of the locality in which the organization is situated. State Enter the name of the state in which the organization is located. Country Enter the name of the country in which the organization is located. Email Address Enter the email address associated with the Certificate Group. Zip Code Enter the zip code. *Validity Unit Select the Validity Unit as either: - Days
- Months
- Years
*Validity Value Enter a Validity Value based on the selected validity unit. *Hash Function Select the Hash Function from the options available in the dropdown. *Key Type Select the Key Type from the options available in the dropdown. *Bit Length Select the Bit Length from the options available in the dropdown. Note: This field will be populated based on the selected Key Type.All asterisk (*) marked fields are mandatory. - Under the Certificate Attributes section, select the Attribute from the available options.
-
Enter a value for the selected attribute.

Table 3. Actions available in the Certificate Attributes grid Action Description 
Allows you to add the attribute to the Certificate Attributes grid. 
Allows you to edit the value of a particular attribute. You can do this by selecting the attribute in the grid, click
, enter the new value
for the attribute, and click
again.
Allows you to delete a certificate attribute. 
Allows you to maximize the Certificate Attributes grid. Search bar Allows you to search for a particular attribute in the grid. -
Under the Vendor Specific Details section, select the field information from
the options available in the dropdown.
Note: This section is displayed only when DigiCert or EJBCA is selected as the Certificate Authority under the CA Details section. The field(s) displayed will vary based on the CA selected.
-
Under the LTM SSL Profile section, enter or select the requested field
information as described in the table below.

Table 4. Field description for LTM SSL Profile section Field Description *Device Vendor Select the device vendor from the options available in the dropdown. *Device Select the device from the options available in the dropdown. Note: This field is populated on the basis of the selected device vendor.*Profile Type Select the profile type from the options available in the dropdown. *Profile Name Enter a meaningful profile name for the profile that is to be created. All asterisk (*) marked fields are mandatory. -
Under the Notifications section, enter the email address(es).
Note: The User email field will auto-populate with the logged in user’s email address by default if the email address has been configured in the SMTP settings. You can also enter a different email address(es) in this field or enter multiple email addresses separated by commas.
-
Click Submit.
AppViewX Certificate is generated and LTM Profile on Server SSL is created successfully.
-
At the Review stage of workflow execution, review the device and profile
name and click Submit.
Note: You can change the profile name at this stage.LTM Profile is created and pushed to the selected F5 device and an email notification is sent to the recipient specified in the input form.

-
To download the certificate, at the View and Download Certificate stage,
hover your mouse over
and from the options displayed, click Download Certificate.
-
Hover your mouse over
to view the Certificate status.

Policy Based
-
Under the CSR Parameters section, enter or select the requested field
information as described in the table below.
Note: Some CSR Parameters will be auto-populated based on the policy associated with the Certificate Group.Note: For more information on the form fields, refer to the field information described in the Manual section.
- Under the Certificate Attributes section, select the Attribute from the available options.
-
Enter a value for the selected attribute.

Table 5. Actions available in the Certificate Attributes grid Action Description 
Allows you to add the attribute to the Certificate Attributes grid. 
Allows you to edit the value of a particular attribute. You can do this by selecting the attribute in the grid, click
, enter the new value
for the attribute, and click
again.
Allows you to delete a certificate attribute. 
Allows you to maximize the Certificate Attributes grid. Search bar Allows you to search for a particular attribute in the grid. -
Under the Vendor Specific Details section, select the field information from
the options available in the dropdown.
Note: This section is displayed only when DigiCert or EJBCA is selected as the Certificate Authority under the CA Details section. The field(s) displayed will vary based on the CA selected.
-
Under the LTM SSL Profile section, enter or select the requested field
information as described in the table below.
Table 6. Field description for LTM SSL Profile section Field Description *Device Vendor Select the device vendor from the options available in the dropdown. *Device Select the device from the options available in the dropdown.
Note: This field is populated on the basis of the selected device vendor.*Profile Type Select the profile type from the options available in the dropdown. *Profile Name Enter a meaningful profile name for the profile that is to be created. All asterisk (*) marked fields are mandatory. -
Under the Notifications section, enter the email address(es).
Note: The User email field will auto-populate with the logged in user’s email address by default if the email address has been configured in the SMTP settings. You can also enter a different email address(es) in this field or enter multiple email addresses separated by commas.
-
Click Submit.
AppViewX Certificate is generated and LTM Profile on Server SSL is created successfully.
-
At the Review stage of workflow execution, review the device and profile
name and click Submit.
Note: You can change the profile name at this stage.LTM Profile is created and pushed to the selected F5 device and an email notification is sent to the recipient specified in the input form.
-
To download the certificate, at the View and Download Certificate stage,
hover your mouse over
and from the options displayed, click Download Certificate.
-
Hover your mouse over
to view the Certificate status.
Upload CSR
-
Under the CSR Parameters section, to Upload CSR, click
.
-
Click Fetch CSR Parameters.
Note: Some CSR parameters are fetched from the uploaded CSR file. For more information on the remaining form fields, refer to the field information described in the Manual section.
- Under the Certificate Attributes section, select the Attribute from the available options.
-
Enter a value for the selected attribute.
Table 7. Actions available in the Certificate Attributes grid Action Description 
Allows you to add the attribute to the Certificate Attributes grid. 
Allows you to edit the value of a particular attribute. You can do this by selecting the attribute in the grid, click
, enter the new value
for the attribute, and click
again.
Allows you to delete a certificate attribute. 
Allows you to maximize the Certificate Attributes grid. Search bar Allows you to search for a particular attribute in the grid. -
Under the Vendor Specific Details section, select the field information from
the options available in the dropdown.
Note: This section is displayed only when DigiCert or EJBCA is selected as the Certificate Authority under the CA Details section. The field(s) displayed will vary based on the CA selected.
-
Under the LTM SSL Profile section, enter or select the requested field
information as described in the table below.
Table 8. Field description for LTM SSL Profile section Field Description *Device Vendor Select the device vendor from the options available in the dropdown. *Device Select the device from the options available in the dropdown. Note: This field is populated on the basis of the selected device vendor.*Profile Type Select the profile type from the options available in the dropdown. *Profile Name Enter a meaningful profile name for the profile that is to be created. All asterisk (*) marked fields are mandatory. -
Under the Notifications section, enter the email address(es).
Note: The User email field will auto-populate with the logged in user’s email address by default if the email address has been configured in the SMTP settings. You can also enter a different email address(es) in this field or enter multiple email addresses separated by commas.
-
Click Submit.
AppViewX Certificate is generated and LTM Profile on Server SSL is created successfully.
-
At the Review stage of workflow execution, review the device and profile
name and click Submit.
Note: You can change the profile name at this stage.LTM Profile is created and pushed to the selected F5 device and an email notification is sent to the recipient specified in the input form.

-
To download the certificate, at the View and Download Certificate stage,
hover your mouse over
and from the options displayed, click Download Certificate.
-
Hover your mouse over
to view the Certificate status.
