Bug ID 2119017: F5OS not able to handle changes to LDAP tls_reqcert configuration

Last Modified: Oct 19, 2025

Affected Product(s):
F5OS F5OS-A, F5OS-C(all modules)

Known Affected Versions:
F5OS-C 1.8.0, F5OS-C 1.8.1, F5OS-C 1.8.2

Opened: Oct 06, 2025

Severity: 3-Major

Symptoms

Changes to an LDAP server's tls_reqcert configuration are not handled by F5OS, resulting in authentication-manager and user-manager communication failures with the LDAP server

Impact

Changes to the LDAP server's tls_reqcert setting will cause communication failures with the LDAP server.

Conditions

- LDAP system authentication configured to authenticate against an Active Directory Server - Under the system Authentication Settings configuration in the Common LDAP Configuration section, "Authenticate with Active Directory" set to True and "Unix Attributes" set to False - LDAP group filters specified for one or more roles - The LDAP server's tls_reqcert configuration is modified while F5OS is actively running.

Workaround

Restart authentication manager and user manager after making configuration changes to the tls_reqcert configuration option.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips