For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

fubarSUSHI's avatar
fubarSUSHI
Icon for Altocumulus rankAltocumulus
Dec 01, 2015

FIPS: Attempting to convert a v10 FIPs key to v11 via tmsh

Im hoping anyone has experience out there to convert a FIPs key via tmsh. The issues I am running into is the actual unique identifier.

 

For example:

 

/config/filestore/files_d/Common_d/certificate_d/certname_12345_1. "12345_1" being the unique identifier.

 

Im trying to avoid converting the key via gui and looking for any option to run it on tmsh.

 

tia

 

1 Reply

  • R_Marc's avatar
    R_Marc
    Icon for Nimbostratus rankNimbostratus

    I've never run version 10 (started on 11.4) but the FIPs stuff, from my experience, is not driven by TMSH, but rather the underlying hardware's firmware and API. The key material is not in a file, though there's a key pointer (I'm assuming they use an openssl engine, but that's just speculation). The Cert, however, isn't stored in hardware so is just like any non-fips key (a PEM encoded key) I've had no issue with keys from version 11.4 to 12.0 (I've had FIPs issues, don't get me wrong..but it's had more to do with the peculiarities of the firmware on the HSM, not with TMSH...specifically around key name length).