Bug ID 582465: Cannot generate key after SafeNet HSM is rebooted

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1

Fixed In:
13.0.0, 12.1.2

Opened: Mar 22, 2016

Severity: 3-Major

Related Article: K53160456

Symptoms

After the SafeNet Hardware Security Module (HSM) is restarted, users cannot generate a new key.

Impact

HSM service is not usable even after restarting pkcs11d. Users must re-authenticate.

Conditions

The BIG-IP system uses the SafeNet HSM.

Workaround

To generate a new key, after HSM finishes starting up, run the following commands: # /shared/safenet/toolkit/sautil -v -s 1 -i 10:11 -c # /shared/safenet/toolkit/sautil -v -s 1 -i 10:11 -o -p <hsm_partition_password> Or, you can reinstall SafeNet client.

Fix Information

After the SafeNet Hardware Security Module (HSM) is restarted, users can now generate a new key.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips