Bug ID 2008381: A TACACS+ server secret with a newline breaks PAM configs and blocks all user logins, including root.

Last Modified: Jul 21, 2026

Affected Product(s):
F5OS F5OS, F5OS-A, F5OS-C(all modules)

Known Affected Versions:
F5OS-A 1.8.0, F5OS-A 1.8.1, F5OS-A 1.8.2, F5OS-A 1.8.3, F5OS-A 1.8.4

Fixed In:
F5OS v2.0.0

Opened: Aug 01, 2025

Severity: 3-Major

Symptoms

When a TACACS+ server secret contains a newline character, the PAM configuration files (/etc/pam.d/password-auth and /etc/pam.d/system-auth) become corrupted. This causes PAM to report "illegal module type" and "expecting return value" errors, preventing all user authentication, including root login via SSH and console.

Impact

TACACS+ authentication to the system is broken.

Conditions

A TACACS+ server is configured with a secret-key value that contains a literal newline character (U+000A). This can occur either by directly submitting a secret containing a newline via the REST API or when the system's primary key is corrupted, causing the decrypted secret value to contain unexpected characters.

Workaround

NA

Fix Information

Fixed in F5 v2.0 version.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips