Bug ID 596619: Some 10.2.x client SSL configurations fail to upgrade to 11.6.1.

Last Modified: Nov 07, 2022

Bug Tracker

Affected Product:  See more info
BIG-IP All, Install/Upgrade(all modules)

Known Affected Versions:
11.6.0, 11.6.0 HF1, 11.6.0 HF2, 11.6.0 HF3, 11.6.0 HF4, 11.6.0 HF5, 11.6.0 HF6, 11.6.0 HF7, 11.6.0 HF8, 11.6.1

Fixed In:
11.6.1 HF1

Opened: May 31, 2016
Severity: 2-Critical
Related Article:
K00539510

Symptoms

Some 10.2.x client SSL configurations fail to upgrade to 11.6.1. The upgrade fails with an error similar to the following: emerg load_config_files: "/usr/libexec/bigpipe load" - failed. -- BIGpipe parsing error (/config/bigpipe/BIG-IP.conf Line 67): 012e0020:3: The requested item (myclientssl {) is invalid (<profile arg> ` show ` list ` edit ` delete ` stats reset) for 'profile'.

Impact

The system fails to upgrade and presents a bigpipe parsing error.

Conditions

Running 10.2.x with a Client SSL profile that has a custom Certificate and Key, and attempting to upgrade to version 11.6.1 or higher.

Workaround

If you have already upgraded and are encountering this issue, do the following: 1. Make a backup copy of /config/bigpipe/BIG-IP.conf. 2. Edit /config/bigpipe/BIG-IP.conf and remove any reference to inherit-certificatechain in the affected ssl profiles. 3. Run /usr/libexec/bigpipe daol. 4. Run tmsh save sys config. 5. Run tmsh load sys config. This should install the configuration after upgrade failure.

Fix Information

A 10.2.x configuration containing a Client SSL profile with a custom Certificate and Key now successfully upgrades to 11.6.1.

Behavior Change