Bug ID 2304897: SELinux audit denials occur when APM uses Active Directory or Kerberos agents

Last Modified: Jul 28, 2026

Affected Product(s):
BIG-IP APM(all modules)

Fixed In:
21.1.0.1, 17.5.1.8, 17.1.3.4

Opened: May 28, 2026

Severity: 2-Critical

Symptoms

SELinux errors similar to below observed in /var/log/auditd/auditd.log: time->Wed May 27 12:16:44 2026 type=PROCTITLE msg=audit(1779909404.672:3492): proctitle=2F7573722F6C6962657865632F61706D64002D640035002D66002D6E003430002D750034 type=SYSCALL msg=audit(1779909404.672:3492): arch=c000003e syscall=250 success=yes exit=9 a0=b a1=338ac093 a2=0 a3=0 items=0 ppid=7778 pid=31621 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="apmd" exe="/usr/libexec/apmd64" subj=system_u:system_r:apd_t:s0 key=(null) type=AVC msg=audit(1779909404.672:3492): avc: denied { read } for pid=31621 comm="apmd" scontext=system_u:system_r:apd_t:s0 tcontext=system_u:system_r:initrc_t:s0 tclass=key

Impact

No behavioural impact

Conditions

APM access policy has AD/Kerberos Auth Agent configured

Workaround

None

Fix Information

The issue has been resolved, and the SELinux errors should no longer appear

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips