Bug ID 507109: inherit-certkeychain attribute of child Client SSL profile can unexpectedly change during upgrade

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP Install/Upgrade, LTM(all modules)

Known Affected Versions:
11.5.1, 11.5.2, 11.5.3, 11.6.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:
12.0.0, 11.6.1, 11.5.4

Opened: Feb 13, 2015

Severity: 3-Major

Related Article: K16589

Symptoms

The inherit-certkeychain attribute of a child Client SSL profile can unexpectedly change after upgrade.

Impact

An incorrect cert key chain is used in the profile.

Conditions

This issue occurs when all of the following conditions are met: -- You create a Client SSL profile that does not inherit the certificate, key, and chain certificate settings from the parent profile. -- You upgrade to BIG-IP 11.5.1 (HF6 or later), 11.5.2, 11.5.3, or 11.6.0.

Workaround

Manually edit bigip.conf to contain the correct value. To do so, add the following line into child client ssl profile: inherit-certkeychain false Run the command: tmsh load sys config

Fix Information

The certificate, key, and chain certificate settings in a Client SSL profile no longer change after an upgrade.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips