Bug ID 622830: LDAP type CRLDP is parsed incorrectly

Last Modified: Jul 18, 2026

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
11.6.1, 11.6.1 hf1, 11.6.1 hf2, 11.6.2, 11.6.2 hf1, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3

Opened: Oct 14, 2016

Severity: 2-Critical

Related Article: K20488861

Symptoms

After upgrading to 11.6.1 HF1, CRLDP authentication stopped working. It can be seen from following sample log that the URL is not parsed correctly: warning apd[15314]: 0149015e:4: fc98d22d: CRLDP Auth agent: CRL lookup failed for LDAP url 'ldap::::389//crl.certificate.../..../certificaterevocationlist?certificateRevocationList' reason 'Invalid CRLDP URL.

Impact

Users may fail access policy evaluation when client certification is used.

Conditions

The problem occurs only when LDAP type CRLDP is available in the client certificate and it is used from the CRL Distribution Points list.

Workaround

Configure other than LDAP type distribution points in the Certificate or if multiple distribution points are present in the client certificate, make sure other than LDAP type scheme succeeds before hitting LDAP CRLDP.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips