Forum Discussion
FIPS: Attempting to convert a v10 FIPs key to v11 via tmsh
I've never run version 10 (started on 11.4) but the FIPs stuff, from my experience, is not driven by TMSH, but rather the underlying hardware's firmware and API. The key material is not in a file, though there's a key pointer (I'm assuming they use an openssl engine, but that's just speculation). The Cert, however, isn't stored in hardware so is just like any non-fips key (a PEM encoded key) I've had no issue with keys from version 11.4 to 12.0 (I've had FIPs issues, don't get me wrong..but it's had more to do with the peculiarities of the firmware on the HSM, not with TMSH...specifically around key name length).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com