Introduction
The nShield Hardware Security Module (HSM) generates and stores a Root of Trust that protects the security objects used by F5 BIG-IP LTM to safeguard user keys and credentials. When operated in FIPS 140-2 Level 2 or Level 3 mode, the HSM meets compliance requirements.
More than one HSM can be enrolled on an F5 BIG-IP machine, provided all HSMs belong to the same Security World.
Product configurations
Entrust has successfully tested nShield HSM integration with F5 BIG-IP in the following configurations. Before using the latest versions tested by Entrust, confirm compatibility with the interoperability matrix.
| Software | Version |
|---|---|
BIG-IP - Virtual Edition |
21.1.0-0.0.38 |
Supported nShield hardware and software versions
Entrust has successfully tested with the following nShield hardware and software versions:
| HSM | Security World Software | Firmware | Image | OCS | Softcard | Module | FIPS Level 3 |
|---|---|---|---|---|---|---|---|
nShield Connect |
13.6.8 |
13.6.16 |
✓ |
✓ |
✓ |
✓ |
|
nShield 5c |
13.6.8 |
13.6.16 |
✓ |
✓ |
✓ |
✓ |
|
Security World v13.6.8 is the last release that supports CentOS 7, the operating system used by the F5 BIG-IP software listed above. Because CentOS 7 has reached end of life (EOL), newer versions of Security World software cannot be used with F5 BIG-IP until F5 updates the underlying operating system shipped with its software. |
Supported nShield HSM functionality
| Feature | Support |
|---|---|
Module-Only key |
Yes |
OCS cards |
Yes |
Softcards |
Yes |
nSaaS |
Yes |
FIPS 140-2 Level 3 |
Yes * |
* F5 BIG-IP SSL profiles that require TLS 1.2 are only supported with Entrust nShield firmware v12.50.11. Contact F5 or Entrust for details on TLS 1.3 support.
Requirements
| The BIG-IP system must be licensed for External Interface and Network HSM. |
Before installing these products, read the associated documentation:
-
For the nShield HSM: Installation Guide and User Guide.
-
If nShield Remote Administration is to be used: nShield Remote Administration User Guide.
-
F5 BIG-IP documentation (https://techdocs.f5.com/en-us/bigip-16-0-0/big-ip-system-and-ncipher-hsm-implementation.html).
In addition, the integration between nShield HSMs and F5 BIG-IP requires:
-
PKCS #11 support in the HSM.
-
A correct quorum for the Administrator Card Set (ACS).
-
Operator Card Set (OCS), Softcard, or Module-Only protection.
-
If OCS protection is used, a 1-of-N quorum must be used.
-
-
Firewall configuration with usable ports:
-
9004 for the HSM (hardserver).
-
The following design decisions also affect how the HSM is installed and configured:
-
Whether your Security World must comply with FIPS 140-2 Level 3 standards.
-
If using FIPS 140-2 Level 3, Entrust recommends creating an OCS for FIPS authorization. The OCS can also provide key protection for the Vault master key. For information about limitations on FIPS authorization, see the Installation Guide for the nShield HSM.
-
-
Whether to instantiate the Security World as recoverable.
| Entrust recommends that you allow only unprivileged connections unless you are performing administrative tasks. |
More information
For more information about OS support, contact your F5 sales representative or Entrust nShield Support at https://nshieldsupport.entrust.com.
| Access to the Entrust nShield Support Portal is available to customers under maintenance. To request an account, contact nshield.support@entrust.com. |