Loading...
Loading...
- In a FIPS-enabled device, upgrading or installing the defective ISO image causes BIGIP to stay in the "INOPERATIVE" state forever due to image integrity failure. - Image integrity failure is caused by the missing or incorrect HMAC for a few modules
BIG-IP is unusable due to the "INOPERATIVE" state
BIG-IP stays in the "INOPERATIVE" state forever in FIPS enabled device
Disabling FIPS is an workaround
N the build sequence, assume first i686 prefetched. Due to perforce mismatch RemoveOutfiles gets called and HMAC CSV file for this module is removed. i686 rebuild completes with newly generated HMAC CSV file for i686 binaries. Then x86_64 prefetched. Due to perforce mismatch RemoveOutfiles gets called and HMAC CSV file for this module is removed. This is leading to the loss of i686 contents from HMAC CSV file which was causing the FIPS integrity to fail in FIPS enabled device. As the fix for the issue, instead of blindly removing the file removed only the arch specific entries from the HMAC CSV file. This fix is preventing the complete loss of HMAC CSV content for one arch when compiling for another arch.
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.