Last Modified: May 29, 2024
Affected Product(s):
BIG-IP TMOS
Fixed In:
17.1.0, 17.0.0.1, 16.1.3
Opened: Apr 22, 2022 Severity: 1-Blocking
- RSA-KEX ciphers list are removed from httpd configuration when FIPS mode is enabled since these are non-approved ciphers for FIPS 140-3 certification. - Mandatory fix for FIPS 140-3 Certification.
- BIG-IP systems running without this fix on a release targeted for certification (BIG-IP 16.1.x or later) will not be running a FIPS 140-3 certified configuration. - https connection using RSA KEX ciphers will not be successful when FIPS 140-3 license is installed in the device.
- BIG-IP versions 16.1.3 and above. - Applies to systems requiring FIPS 140-3 Certification. - FIPS 140-3 license is installed on BIG-IP or its a FullBoxFIPS device. - https connections are established using the RSA-KEX based ciphers
None
Apply this fix to ensure that the system is compliant with FIPS 140-3 Certification.