Bug ID 464289: Duplicate TACACS user account handling might cause unexpected results.

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
11.4.1, 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10

Fixed In:
11.6.0

Opened: May 26, 2014

Severity: 3-Major

Related Article: K06504193

Symptoms

Duplicate TACACS user account handling might cause unexpected results.

Impact

Login might succeed for the local user with one role where it would not succeed for the remote user with a different role. This occurs when using substitution strings (essentially a placeholder string) instead of the actual value that matches the user account information.

Conditions

Multiple accounts (one local and one remote) with different roles in the same partition. Normally, configuration data validation is performed at the configuration time. However, if TACACS variable substitution is used, this validation can only be performed at user login time.

Workaround

None.

Fix Information

Duplicate TACACS user account (local and remote) are now handled as expected.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips