Bug ID 824757: SSL traffic fails with Equinix netHSM on device restart

Last Modified: Sep 14, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 14.1.4.4, 14.1.4.5, 14.1.4.6, 14.1.5, 14.1.5.1, 14.1.5.2, 14.1.5.3, 14.1.5.4, 14.1.5.6, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4

Fixed In:
15.1.0

Opened: Sep 11, 2019

Severity: 2-Critical

Symptoms

SSL traffic with Equinix netHSM keys fails if TMM process is restarted or device is restarted.

Impact

SSL traffic fails.

Conditions

This issue occurs when following conditions are met: 1. Virtual server configured with SSL profile containing Equinix netHSM keys. 2. Device or TMM process is restarted

Workaround

Manually restart the pkcs11d process: tmsh restart sys service pkcs11d

Fix Information

SSL traffic with Equinix netHSM keys no longer fails if TMM process is restarted or device is restarted.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips