Bug ID 1591813: [APM][SAML] SP automation fails with error message 'cannot update (cert_type)'

Last Modified: Mar 18, 2025

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
15.1.10, 15.1.10.2, 15.1.10.3, 15.1.10.4, 15.1.10.5, 15.1.10.6

Opened: Jun 05, 2024

Severity: 4-Minor

Symptoms

Whenever a certificate is updated while fetching the metadata from the metadata URL in SAML automation for creating SP connector, an error occurs: err mcpd[8894]: 01070712:3: Caught configuration exception (0), file:(/Common/sp_cert.crt) cannot update (cert_type).

Impact

Connector automation fails to create SP Connectors with new certificates.

Conditions

- Configure BIG-IP as IDP with SP automation objects (metadata URL as internal virtual server URL) - Configure a internal virtual server and attach an iRule to get the iFile based on the URI. (https://1.1.1.1/PS0028JP) -. Update the iFiles that returns metadata and wait till the SP-automation to update its sp-connector objects PS0028JP -> ifile that returns metadata of SP with different cert ( self signed to CA and viceversa)

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips