Bug ID 2261045: CNE controller not using new certs after root CA update

Last Modified: Jul 28, 2026

Affected Product(s):
BIG_IP_NEXT(BNK) BNK(all modules)

Fixed In:
2.3.0

Opened: Apr 01, 2026

Severity: 3-Major

Symptoms

CNE controller fails to use the new certificates after the root CA is updated.

Impact

GRPC communication fails, TMM is not configured.

Conditions

After the Root CA update and reissued certs, TMM’s certificate chain uses a different root CA than the controller’s.

Workaround

Restart the controller.

Fix Information

Improve TLS error handling, to refresh certs in cases where Root CA mismatch is the reason for failed communication.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips