Bug ID 895021: Error log when listing with tmsh ECDSA fips key

Last Modified: Oct 17, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1, 16.0.1.2

Opened: Apr 01, 2020

Severity: 4-Minor

Symptoms

Error log appears in /var/log/ltm when tmsh lists FIPS ECDSA keys: err tmsh[23337]: error: fips-codec1 Failed to get length of attribute 3 for FIPS key 8. FIPS 0x000000af.

Impact

There is no functional impact; the keys are correctly listed, but an error log appears in /var/log/ltm: 10350f1.example.net err tmsh[23337]: error: fips-codec1 Failed to get length of attribute 3 for FIPS key 8. FIPS 0x000000af : HSM Error: Invalid attribute type in the object template

Conditions

1. FIPS card contains ECDSA DNSSEC Key. 2. Listing FIPS keys with: tmsh show sys crypto fips key.

Workaround

None.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips