Forum Discussion

Margvin's avatar
Margvin
Icon for Cirrus rankCirrus
Dec 02, 2023

anomali log err tmm4[22477]: 01010282:3: Crypto codec error: qat-crypto01 Could not get ECDH other p

HI

I see a log anomali and Level Error in LOG LTM 

err tmm4[22477]: 01010282:3: Crypto codec error: qat-crypto01 Could not get ECDH other public value point.

 

does this disrupt traffic? or are there any other impacts besides that?

    • Margvin's avatar
      Margvin
      Icon for Cirrus rankCirrus

      It's BIG-IP v14.1.4.4 (Build 0.0.4) and Hardware Device

       

  • This error indicates that SSL negotiation failed. Normally a single SSL negotiation failure isn't too important because the internet is a big wild place. We do have a request open to change this error to low-severity so it will be filtered out by default:

    https://my.f5.com/manage/s/article/K64201029

    If you are seeing this log regularly while troubleshooting a problem, like one cilent can't connect consistently or the like, you can follow the recommended procedures in the TLS troubleshooting article here:

    https://my.f5.com/manage/s/article/K15292

     

  • I've encountered a similar error in my logs before, and it can be a bit concerning. The "Crypto codec error" you're seeing, specifically "qat-crypto01 Could not get ECDH other public value point," usually points to an issue with the cryptographic functions. In terms of traffic disruption, it could potentially impact the functionality, especially if the system relies on cryptographic operations. The error suggests a problem with the Elliptic Curve Diffie-Hellman (ECDH) key exchange, which is often used for secure communications.