Bug ID 1012645: Config load fails with HTTP2 profile when serverssl has renegotiation enabled

Last Modified: Apr 11, 2024

Affected Product(s):
BIG-IP Install/Upgrade, LTM(all modules)

Known Affected Versions:
13.1.4, 13.1.4.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 14.1.4.4, 15.1.3, 15.1.3.1, 15.1.4, 16.0.1.2, 16.1.0, 16.1.1

Fixed In:
17.0.0, 16.1.2, 15.1.4.1, 14.1.4.5, 13.1.5

Opened: Apr 20, 2021

Severity: 4-Minor

Symptoms

Configuration load fails with an error: 0107186b:3: Invalid "enforce-tls-requirements" value for profile /Common/http2. In Virtual Server (/Common/vs1) an http2 profile with enforce-tls-requirements enabled is incompatible with client-ssl/server-ssl profile with renegotiation enabled. Value must be disabled. Unexpected Error: Loading configuration process failed.

Impact

The configuration fails to load.

Conditions

Virtual server with: 1. Clientssl profile with renegotiation disabled. 2. Serverssl profile with renegotiation enabled. 3. The HTTP2 profile is attached to the client side only.

Workaround

Manually disable renegotiation on the serverssl profile, then reload the configuration.

Fix Information

N/A

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips