Bug ID 762385: Wrong remote-role assigned using LDAP authentication after upgrade to 14.1.x and later

Last Modified: May 29, 2024

Affected Product(s):
BIG-IP Install/Upgrade, TMOS(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4

Fixed In:
15.1.0, 14.1.2.3

Opened: Mar 20, 2019

Severity: 2-Critical

Symptoms

When multiple attributes in a list match multiple roles, the wrong role may be assigned. Alternatively, authentication may fail when check-roles-group is disabled.

Impact

BIG-IP assigns the user to the last attribute in the list that matches a role, potentially yielding a more restrictive set of permissions. Authentication may fail when check-roles-group is disabled.

Conditions

LDAP server replies with a list of attributes (e.g., list of memberOf) where more than one match existing role.

Workaround

None.

Fix Information

The correct remote-role is now assigned using LDAP authentication.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips