Bug ID 953845: After re-initializing the onboard FIPS HSM, may lose access after second MCPD restart

Last Modified: Oct 13, 2020

Bug Tracker

Affected Product:  See more info
BIG-IP All(all modules)

Known Affected Versions:
16.0.0.1, 16.0.0

Opened: Oct 09, 2020
Severity: 3-Major

Symptoms

When re-initializing an onboard HSM on particular platforms, BIG-IP may disconnect from the HSM after a second restart of the MCPD daemon. This can occur when using administrative commands such as: -- tmsh run util fips-util init -- fipsutil init -- tmsh run util fips-util loginreset -r -- fipsutil loginreset -r

Impact

BIG-IP is unable to communicate with the onboard HSM.

Conditions

-- Using the following platforms: + i5820-DF / i7820-DF + 5250v-F / 7200v-F + 10200v-F + 10350v-F + vCMP guest on i5820-DF / i7820-DF + vCMP guest on 10350v-F

Workaround

The last step in using "fipsutil init" is to restart all system services ("tmsh restart sys service all") or reboot. Immediately before doing this: -- open /config/bigip.conf in a text editor (e.g. vim or nano) -- locate and delete the configuration "sys fipsuser f5cu" stanza, e.g.: sys fipsuser f5cu { password $M$Et$b3R0ZXJzCg== }

Fix Information

None

Behavior Change