Forum Discussion
Thales integration
I'm trying to understand how F5 uses the Thales HSM. It would appear to me that the F5
(a) generates a key pair without using the HSM, storing locally (b) imports the private key only into the Thales HSM Security World
Given this understanding, I'm trying to understand the benefit derived from using the Thales HSM?
(a) The HSM hardware isn't being used for random number generation! (b) The private key exists out with the HSM Security World!
Seems less than ideal to me? or am I missing something?
1 Reply
- Kevin_Stewart
Employee
An incorrect assumption.
The integration allows the BIG-IP to access key functions of the Thales, so key generation is actually happening on the Thales itself, and the "key" in the BIG-IP keystore is simply a pointer to the Thales protected key. Here's more information:
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com