Introduction

The nShield Hardware Security Module (HSM) generates and stores a Root of Trust that protects the security objects used by F5 BIG-IP LTM to safeguard user keys and credentials. When operated in FIPS 140-2 Level 2 or Level 3 mode, the HSM meets compliance requirements.

More than one HSM can be enrolled on an F5 BIG-IP machine, provided all HSMs belong to the same Security World.

Product configurations

Entrust has successfully tested nShield HSM integration with F5 BIG-IP in the following configurations. Before using the latest versions tested by Entrust, confirm compatibility with the interoperability matrix.

Software Version

BIG-IP - Virtual Edition

21.1.0-0.0.38

Supported nShield hardware and software versions

Entrust has successfully tested with the following nShield hardware and software versions:

HSM Security World Software Firmware Image OCS Softcard Module FIPS Level 3

nShield Connect

13.6.8

12.72.4 (FIPS 140-2 certified)

13.6.16

nShield 5c

13.6.8

13.4.5 (FIPS 140-3 certified)

13.6.16

Security World v13.6.8 is the last release that supports CentOS 7, the operating system used by the F5 BIG-IP software listed above. Because CentOS 7 has reached end of life (EOL), newer versions of Security World software cannot be used with F5 BIG-IP until F5 updates the underlying operating system shipped with its software.

Supported nShield HSM functionality

Feature Support

Module-Only key

Yes

OCS cards

Yes

Softcards

Yes

nSaaS

Yes

FIPS 140-2 Level 3

Yes *

* F5 BIG-IP SSL profiles that require TLS 1.2 are only supported with Entrust nShield firmware v12.50.11. Contact F5 or Entrust for details on TLS 1.3 support.

Requirements

The BIG-IP system must be licensed for External Interface and Network HSM.

Before installing these products, read the associated documentation:

In addition, the integration between nShield HSMs and F5 BIG-IP requires:

  • PKCS #11 support in the HSM.

  • A correct quorum for the Administrator Card Set (ACS).

  • Operator Card Set (OCS), Softcard, or Module-Only protection.

    • If OCS protection is used, a 1-of-N quorum must be used.

  • Firewall configuration with usable ports:

    • 9004 for the HSM (hardserver).

The following design decisions also affect how the HSM is installed and configured:

  • Whether your Security World must comply with FIPS 140-2 Level 3 standards.

    • If using FIPS 140-2 Level 3, Entrust recommends creating an OCS for FIPS authorization. The OCS can also provide key protection for the Vault master key. For information about limitations on FIPS authorization, see the Installation Guide for the nShield HSM.

  • Whether to instantiate the Security World as recoverable.

Entrust recommends that you allow only unprivileged connections unless you are performing administrative tasks.

More information

For more information about OS support, contact your F5 sales representative or Entrust nShield Support at https://nshieldsupport.entrust.com.

Access to the Entrust nShield Support Portal is available to customers under maintenance. To request an account, contact nshield.support@entrust.com.