Bug ID 517957: RSA 2 factor authentication pin is saved when password policy is set to cache password

Last Modified: Oct 07, 2023

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 12.1.0 HF1, 12.1.0 HF2, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:
12.1.0, 12.0.0

Opened: Apr 14, 2015

Severity: 3-Major

Symptoms

User will see previously used RSA pin in the login page

Impact

User sees pre-populated stale pin in logong page

Conditions

Access policy has RSA 2 factor authentication configured Password policy in NA setting is set to cache passwords

Workaround

Delete the pin in logon page and enter correct pin.

Fix Information

RSA pin is not cached now irrespective of the password caching policy

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips