Bug ID 577474: Users with auditor role are unable to use tmsh list sys crypto cert

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
11.6.1, 11.6.1 HF1, 11.6.1 HF2, 11.6.2, 11.6.2 HF1, 12.0.0, 12.0.0 HF1, 12.0.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:
13.0.0, 12.1.3, 11.6.3

Opened: Mar 02, 2016

Severity: 3-Major

Related Article: K35208043

Symptoms

The system returns error messages after running the following command: tmsh list sys crypto cert. Error messages appear similar to the following: -- Key management library returned bad status: -4, Invalid Parameter. -- Unexpected Error: Can't chmod key management directory: "/var/tmp/key_mgmt", error: [1] Operation not permitted".

Impact

BIG-IP users with the auditor role cannot view certificates using the command: list sys crypto cert.

Conditions

-- BIG-IP user accounts configured with the auditor role. -- Running the command: tmsh list sys crypto cert.

Workaround

Use the following command: sys file ssl-cert For example, use either of the following: -- list sys file ssl-cert default.crt -- list sys file ssl-cert

Fix Information

BIG-IP users with the auditor users can now see certificates using the following command: list sys crypto cert.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips