Bug ID 1688309: Using expired chain from bundle when it contains a valid chain

Last Modified: Oct 15, 2025

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
17.1.1.2, 17.1.1.3, 17.1.1.4, 17.1.2, 17.1.2.1, 17.1.2.2, 17.1.3

Opened: Oct 01, 2024

Severity: 3-Major

Symptoms

SSL handshake failure with chain includes expired certificate.

Impact

Handshake failures once the certificate in the chain expires.

Conditions

Bundle contains expired and valid chains that can used to verify trust and the expired cert is one depth apart from the valid chain. For example. leaf->a->b->c, where b->c is expired leaf->a->c, which is valid

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips