Last Modified: Sep 01, 2026
Affected Product(s):
BIG-IP (all modules)
Known Affected Versions:
17.1.3.4, 17.5.1.8, 21.0.0.3, 21.1.0.1
Opened: Jul 07, 2026 Severity: 3-Major
* SSL/TLS handshake failures with "certificate unknown" alert * Certificate validation fails when an intermediate CA is used as a trusted CA * OCSP response control set to "Ignore" is not honored in server-ssl profiles * Connections fail in both forward and reverse proxy scenarios
* SSL/TLS connections fail when intermediate CA certificates are used as trusted CAs in SSL profiles * Affects both client-ssl and server-ssl profile configurations * Prevents proper certificate validation in proxy scenarios * Admin users cannot configure intermediate CAs as trusted CAs without workarounds.
Server-SSL Profile (Reverse Proxy): * When an intermediate CA certificate is configured as a trusted CA (ca-file) -> FAILS * When root CA is configured as trusted CA -> PASSES OCSP "Ignore" setting is not respected Client-SSL Profile (Forward Proxy): * When bundle containing root + intermediate CAs is used -> PASSES * When intermediate CA alone is configured as a trusted CA -> FAILS
Use a certificate bundle containing both root CA and intermediate CA certificates instead of using the intermediate CA alone as the trusted CA.
None