Bug ID 1301357: Initial Password Settings insufficient for security certifications

Last Modified: Oct 08, 2025

Affected Product(s):
F5OS F5OS-A, F5OS-C(all modules)

Known Affected Versions:
F5OS-A 1.5.0, F5OS-A 1.5.1, F5OS-A 1.5.2, F5OS-A 1.5.3

Fixed In:
F5OS-C 1.6.0

Opened: May 22, 2023

Severity: 2-Critical

Symptoms

When an admin-role user sets another user's password using set-password, the user was not always forced to change their password on first login with the new credentials. Modern security standards all require that users establish their own credentials.

Impact

Credentials are not always required to be set upon initial access.

Conditions

If a user set their own initial password, and an admin-role user later changed it to some other value, the user was not always forced to reset it on first use.

Workaround

None

Fix Information

The 'set-password' command now always resets the password last-change time to zero, which forces a password change on next login.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips