Bug ID 2179369: F5OS does not validate the LDAP TLS CA certificate

Last Modified: Dec 11, 2025

Affected Product(s):
F5OS F5OS-A, F5OS-C(all modules)

Known Affected Versions:
F5OS-A 1.5.1, F5OS-A 1.5.2, F5OS-A 1.5.3, F5OS-A 1.5.4, F5OS-A 1.8.0, F5OS-A 1.8.3, F5OS-C 1.6.2, F5OS-C 1.6.4, F5OS-C 1.8.0, F5OS-C 1.8.1, F5OS-C 1.8.2

Opened: Dec 03, 2025

Severity: 3-Major

Symptoms

F5OS does not validate that LDAP CA cert config (system aaa authentication ldap tls_cacert) is a valid CA certificate. An error similar to the following will be logged: authd[7]: priority="Err" version=1.0 msgid=0x3901000000000101 msg="LDAP API error during : -" oper="SASL bind" code=-1 msg="Can't contact LDAP server".

Impact

Remote LDAP authentication does not work.

Conditions

-- F5OS system configured to use remote authentication via LDAP. -- Invalid ldap tls_cacert configured.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips