Bug ID 2207893: Error seems to indicate DTDI not DTCA certificate has expired

Last Modified: Sep 02, 2026

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
17.5.1.3, 17.5.1.4, 17.5.1.5, 17.5.1.6, 17.5.1.8

Fixed In:
21.1.0.2, 17.5.1.9, 17.1.3.5

Opened: Jan 19, 2026

Severity: 4-Minor

Symptoms

Error seems to indicate DTDI not DTCA certificate, has expired: Unexpected Error: Could not add device (error from devmgmtd): The device (/Common/error-bigip2.moskal) certificate expired on Jan 16 13:00:19 2026 GMT

Impact

- The error when a device trust member is being added is misleading for the customers - The error seems to indicate the DTDI certificate has expired, not the DTCA certificate

Conditions

Configure an HA pair of BIGIP devices and set the system clock back just over 10 years. Regenerate the trust domain and update the date back to the present day, then try to add a Device Trust Member

Workaround

Reset device trust and generate a new CA certificate, and then re-establish device trust

Fix Information

Changed the code for the error msg to indicate that DTCA certificate has expired instead of DTDI

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips