Bug ID 1974801: Deprecated PKCSv1.5 in Marvell affects r5000-DF and r10000-DF Platforms

Last Modified: Nov 25, 2025

Affected Product(s):
BIG-IP LTM(all modules)

Fixed In:
21.0.0

Opened: Jun 30, 2025

Severity: 3-Major

Symptoms

- SSL profile configuration fails with Marvell HSM keys - SSL handshake fails during runtime - Configuration rejection messages in UI/API - Runtime errors and aborted connections

Impact

Configuration rejections and handshake failures

Conditions

All 6 conditions must be present: Platform: Marvell r5000-DF or r10000-DF F5OS Version: = 1.5.3 FIPS Firmware: = 2.09 SSL profile references Marvell on-board HSM key Cipher list includes only RSA key exchange Attempting PKCS#1 v1.5 padding operations

Workaround

Update Cipher Suites (Primary recommendation) - Use ECDHE instead of RSA key exchange

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips