Bug ID 596619: Some 10.2.x client SSL configurations fail to upgrade to 11.6.1.

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP All, Install/Upgrade(all modules)

Known Affected Versions:
11.5.1 HF1, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4, 11.5.1 HF5, 11.5.1 HF6, 11.5.1 HF7, 11.5.1 HF8, 11.5.1 HF9, 11.5.1 HF10, 11.5.1 HF11, 11.5.2 HF1, 11.5.3 HF1, 11.5.3 HF2, 11.5.4 HF1, 11.5.4 HF2, 11.5.4 HF3, 11.5.4 HF4

Fixed In:
11.6.1 HF1

Opened: May 31, 2016

Severity: 2-Critical

Related Article: K00539510

Symptoms

Some 10.2.x client SSL configurations fail to upgrade to 11.6.1. The upgrade fails with an error similar to the following: emerg load_config_files: "/usr/libexec/bigpipe load" - failed. -- BIGpipe parsing error (/config/bigpipe/BIG-IP.conf Line 67): 012e0020:3: The requested item (myclientssl {) is invalid (<profile arg> ` show ` list ` edit ` delete ` stats reset) for 'profile'.

Impact

The system fails to upgrade and presents a bigpipe parsing error.

Conditions

Running 10.2.x with a Client SSL profile that has a custom Certificate and Key, and attempting to upgrade to version 11.6.1 or higher.

Workaround

If you have already upgraded and are encountering this issue, do the following: 1. Make a backup copy of /config/bigpipe/BIG-IP.conf. 2. Edit /config/bigpipe/BIG-IP.conf and remove any reference to inherit-certificatechain in the affected ssl profiles. 3. Run /usr/libexec/bigpipe daol. 4. Run tmsh save sys config. 5. Run tmsh load sys config. This should install the configuration after upgrade failure.

Fix Information

A 10.2.x configuration containing a Client SSL profile with a custom Certificate and Key now successfully upgrades to 11.6.1.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips