Bug ID 601828: An untrusted certificate can cause tmm to crash.

Last Modified: Oct 16, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2

Fixed In:
13.0.0, 12.1.2 HF1, 11.6.3.1

Opened: Jun 28, 2016

Severity: 2-Critical

Related Article: K13338433

Symptoms

If the certificate sent by an SSL server to the server-side BIG-IP profile is untrusted, tmm might crash.

Impact

Traffic disrupted while tmm restarts.

Conditions

-- Server-side SSL profile is attached to a virtual server. -- The SSL server sends an untrusted certificate to the BIG-IP system.

Workaround

None.

Fix Information

The BIG-IP system will now log the certificate name 'unknown' if an SSL server sends an untrusted certificate, and tmm does not restart.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips