Bug ID 1141661: LDAP groups configurable with custom gidNumber to role mappings

Last Modified: Jun 04, 2025

Affected Product(s):
F5OS Velos(all modules)

Known Affected Versions:
F5OS-A 1.0.0, F5OS-A 1.0.1, F5OS-A 1.1.0, F5OS-A 1.1.1, F5OS-A 1.3.0, F5OS-A 1.3.1, F5OS-A 1.3.2, F5OS-C 1.0.0, F5OS-C 1.1.0, F5OS-C 1.1.1, F5OS-C 1.1.2, F5OS-C 1.1.3, F5OS-C 1.1.4, F5OS-C 1.5.0, F5OS-C 1.5.1

Fixed In:
F5OS-C 1.6.0, F5OS-A 1.4.0

Opened: Aug 24, 2022

Severity: 3-Major

Symptoms

In prior releases, the group ID number representing authentication roles was hard-coded to certain values. This could cause problems since an external authentication system (for example, LDAP) may have conflicting group IDs.

Impact

This could cause difficulty configuring a user with specific role assignments in an external authentication system.

Conditions

External authentication system (e.g. LDAP, AD, or radius) where a group ID number conflicts with the hard-coded role IDs (for example, 9000).

Workaround

Reconfigure group IDs in external system such that the hard-coded group ID numbers match the role numbers required by the F5 system.

Fix Information

Added configuration to allow the administrator to specify the group ID number in use by the external system to identify user roles. The external number will be mapped to the F5 role based on this setting.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips