Bug ID 699091: SELinux denies console access for remote users.

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4

Fixed In:
14.0.0, 13.1.3.5, 12.1.5.3

Opened: Dec 15, 2017

Severity: 3-Major

Symptoms

SELinux denies console access for remote users if they are attempting to log in for the first time. This occurs because the user has not logged in before, so no entries exist for them in the userrolepartitions file.

Impact

Certain remote users may not be able to log in to the console.

Conditions

-- Remote authentication is enabled. -- BIG-IP system user attempts to log in to the console as their first login.

Workaround

Login as a remote user using SSH or the GUI.

Fix Information

Allow login to connect to MCP to announce remote user login and set user role partition access.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips