Forum Discussion
Cory_50405
Noctilucent
I have some FIPS boxes and here's what I've found from testing. If you run 'fipsutil info' from bash shell, there can be two results:
Uninitialized FIPS card will present an error like this:
fipsutil error (line 1159): Library Initialization : 0x05 : Undefined Error Code
Initialized FIPS card will display something like this:
Label: F5FIPS
HSM Serial Number: xxxxxxx
Hardware ID: 0x0
Firmware Version: 4.7.1
Total FLASH: 14286412
Free FLASH: 14239436
Total SRAM: 16984736
Free SRAM: 16979488
As Kevin states though, keys don't have to be stored in the HSM even though it's initialized. You can create keys without putting them in the HSM. You can also move them to the HSM at a later point if you so choose.
Chris_FP
May 23, 2014Cirrus
I ran the fipsutil info command on some other boxes and it didn't show the error code but the info. However I know for a fact that the fips card wasn't initialised as I put the boxes in and I specifically didn't initialise them - maybe they were done by F5 before shipping?
My follow up question is:- Does that mean that all SSL is being processed by the FIPS card, even though no cert/key are stored there or is SSL still being processed by the dedicated [F5] SSL hardware