Last Modified: Jan 06, 2020
See more info
BIG-IP DNS, GTM
Known Affected Versions:
11.5.1, 11.5.1 HF1, 11.5.1 HF10, 11.5.1 HF11, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4, 11.5.1 HF5, 11.5.1 HF6, 11.5.1 HF7, 11.5.1 HF8, 11.5.1 HF9, 11.5.2, 11.5.2 HF1, 11.5.3, 11.5.3 HF1, 11.5.3 HF2, 11.5.4, 11.5.4 HF1, 11.5.4 HF2, 11.5.4 HF3, 11.5.4 HF4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 13.1.0, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124, 13.1.1, 126.96.36.199, 188.8.131.52, 184.108.40.206, 220.127.116.11, 18.104.22.168, 13.1.3, 22.214.171.124, 126.96.36.199
Opened: Jul 13, 2017
A DNSSEC key generation event is scheduled to occur (for example an expiration or rollover) while the Master Key is not yet initialized and mcpd is not in a full running state. The DNSSEC key generation fails because of the unavailability of the Master Key, but uninitialized mcpd may be unable to roll-back the transaction, resulting in syncing an empty DNSSEC key to the GTM sync group.
It is possible that empty DNSSEC keys could be synced to the GTM sync group, over-writing previously valid key generations.
A DNSSEC key generation event is scheduled to occur (for example an expiration or rollover) during the time in which he Master Key is not yet initialized and mcpd is not in a full running state. This could be when a BIG-IP is being rebooted, performing a bigstart restart, or has been powered-off for some time and is being powered back up.
When powering off a GTM for an extended period of time, it is advisable to first remove the GTM from the sync group, so that whenever it is powered on again, it does not attempt sync before it is in a healthy state. You can also avoid this issue by performing reboot or bigstart restart during a window of time in which DNSSEC keys are not scheduled to expire or rollover.
Now if a DNSSEC key generation event occurs (for example an expiration or rollover) while the Master Key is not yet initialized, BIG-IP will delay all DNSSEC key generation events until the Master Key becomes available. A message will be logged in /var/log/ltm to inform the user that BIG-IP is delaying DNSSEC key generations for this reason.