Last Modified: Feb 28, 2025
Affected Product(s):
BIG-IP LTM
Fixed In:
17.5.0, 17.1.2
Opened: Oct 29, 2024 Severity: 3-Major
By default, keys can be created or imported into the onboard FIPS HSM.
Private keys can be created and imported into the FIPS card.
Create or import private keys into the onboard FIPS HSM.
None
Added an option "-k ... Disable PEM key import during INIT." to fipsutil to prevent the import of keys into the HSM. This option is to be provided as input to fipsutil when initializing the partition in the tenant. Once initialized with this option, key import restriction applies until the partition is re-initialized. This cannot be modified while the partition is in use.