Bug ID 1006357: Config load failure upon upgrade from newer maintenance releases to older versions when APM has AD AAA objects configured

Last Modified: Oct 15, 2021

Bug Tracker

Affected Product:  See more info
BIG-IP APM, Install/Upgrade(all modules)

Known Affected Versions:
12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 13.1.4.1, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 14.1.4.4, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 15.1.3.1, 15.1.4, 16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1, 16.0.1.2, 16.1.0

Opened: Mar 25, 2021
Severity: 3-Major

Symptoms

Upgrade fails during config load, and reports an error: 01420001:2: Can't load keyword definition (aaa-active-directory-server.kdc_validation) : framework/SchemaCmd.cpp, line 825 "/usr/bin/tmsh -n -g -a load sys config partitions all " - failed. -- Loading schema version: 14.1.4

Impact

The BIG-IP system goes to the 'INOPERATIVE' state and traffic is disrupted.

Conditions

-- BIG-IP system is running one of the following versions: BIG-IP 12.1.6 or later 12.x software BIG-IP 13.1.4 or later 13.x software BIG-IP 14.1.4 or later 14.x software BIG-IP 15.1.3 or later 15.x software -- Configure APM AAA AD objects -- Attempt to upgrade to earlier maintenance releases or point releases, for example: BIG-IP 12.1.5.x or earlier 12.x software BIG-IP 13.1.3.x or earlier 13.x software BIG-IP 14.1.3 or earlier 14.x software BIG-IP 15.1.2 or earlier 15.x software BIG-IP 16.0.x or earlier 16.x software

Workaround

Upgrades work as expected in the following compatible maintenance releases: ---BIG-IP 12.1.6 BIG-IP 12.1.6 or later BIG-IP 13.1.4 or later BIG-IP 14.1.4 or later BIG-IP 15.1.3 or later BIG-IP 16.1.0 or later ---BIG-IP 13.1.4 BIG-IP 13.1.4 or later BIG-IP 14.1.4 or later BIG-IP 15.1.3 or later BIG-IP 16.1.0 or later ---BIG-IP 14.1.4 BIG-IP 14.1.4 or later BIG-IP 15.1.3 or later BIG-IP 16.1.0 or later ---BIG-IP 15.1.3 BIG-IP 15.1.3 or later BIG-IP 16.1.0 or later ---BIG-IP 16.1.0 BIG-IP 16.1.0 or later Note ===== If you still want to continue upgrade to a version which is not supported, remove the APM AAA AD objects prior to upgrading. The upgrade should then succeed as expected. Once the upgrade is successful, configure the AAA AD objects and related configurations again.

Fix Information

None

Behavior Change