Last Modified: Sep 13, 2023
17.1.0, 188.8.131.52, 16.1.3
Opened: Apr 22, 2022 Severity: 1-Blocking
- RSA-KEX ciphers list are removed from httpd configuration when FIPS mode is enabled since these are non-approved ciphers for FIPS 140-3 certification. - Mandatory fix for FIPS 140-3 Certification.
- BIG-IP systems running without this fix on a release targeted for certification (BIG-IP 16.1.x or later) will not be running a FIPS 140-3 certified configuration. - https connection using RSA KEX ciphers will not be successful when FIPS 140-3 license is installed in the device.
- BIG-IP versions 16.1.3 and above. - Applies to systems requiring FIPS 140-3 Certification. - FIPS 140-3 license is installed on BIG-IP or its a FullBoxFIPS device. - https connections are established using the RSA-KEX based ciphers
Apply this fix to ensure that the system is compliant with FIPS 140-3 Certification.