Forum Discussion

AP_303498's avatar
AP_303498
Icon for Nimbostratus rankNimbostratus
Jan 31, 2018

Secp521r1 curve support in Big IP LTM?

Hi!

 

We are currently running version 11.6.2HF1. We have some new CA certificates which we would like to import to our system, but hit a problem with supported curves. Import gives following error:

 

010717e6:3: EC key contains unsupported curve.

 

Current version seems to support only prime256v1 and secp384r1 curves, but our certificate used secp521r1. Is there support for this in 12 or 13? Or is this something that isn't supported yet?

 

1 Reply

  • Maybe not needed anymore, but an anwser is better then none.

     

    It seems secp521r1 is only supported for IPSec connections, since version 12.

     

    See: https://support.f5.com/csp/article/K12982

     

    Hit his same problem, need this for client cert authentication.

     

    Regards,

     

    Axel.