Bug ID 619872: BigIP upgrading doesn't carry over Thales configuration on the secondary slot

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
12.1.0, 12.1.1, 12.1.2, 12.1.3,,,,,,,, 12.1.4,, 12.1.5,,,, 12.1.6

Fixed In:

Opened: Sep 30, 2016

Severity: 3-Major


After BIG-IP upgrading in the multi-blade platform configured with Thales, the secondary platform fails to carry over Thales configuration. When running enquiry at primary slot, you will get response about Thales config. At secondary slot, you will not be able to run "enquiry".


Secondary slot doesn't have Thales HSM configured.


Thales installed on chassis.


Wait for csynced finish syncing /shared/nfast from primary slot to the secondary slot. Then run "clsh bigstart restart pkcs11d". While waiting, run this command to compare the folder size of /shared/nfast/. [root@localhost:/S1-green-P:Active:Standalone] config # clsh "du -sh /shared/nfast/" === slot 2 addr color green === 220M /shared/nfast/ === slot 3 addr color red === === slot 4 addr color blue === === slot 1 addr color green === 220M /shared/nfast/ Another workaround(maybe faster) is to reinstall Thales after upgrading. Csyncd could take 10+ minutes to finish sync'ing. A third workaround is to scp /shared/nfast/ from primary slot to secondary slot. After that, run "bigstart restart pkcs11d" e.g., [root@localhost:/S1-green-P:Active:Standalone]scp -r /shared/nfast/ slot2:/shared/

Fix Information


Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips