Bug ID 1562669: [APM]Access Policy Export does not write certificate authority profile correctly to ng_export.conf

Last Modified: Sep 13, 2024

Affected Product(s):
BIG-IP APM(all modules)

Opened: Mar 15, 2024

Severity: 3-Major

Symptoms

When a machine cert check agent is used in an access policy and references a certificate authority profile, policy export does not create the object properly in the ng_export.conf file. This causes the subsequent import to fail. 1. Export policy from 17.1.1 2. Attempt to import into another APM on 17.1.1 3. In the GUI it refreshes, but never imports. 4. Import command fails with this error: 21:12:06 0 error: 01020036:3: The requested profile_certificateauthority (/Common/my-ca) was not found. Unexpected Error: Loading configuration process failed.

Impact

Can not import the access policy into a different APM.

Conditions

Importing a policy from one APM system into another APM system.

Workaround

Modify the ng_export.conf file to add @name- in the certificate-authority profile object: ltm profile certificate-authority /@partition/@name-my-ca {

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips