Bug ID 663924: Qkview archives includes Kerberos keytab files

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
11.5.4, 11.5.5, 11.5.6, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.6.3.1, 11.6.3.2, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1

Fixed In:
13.1.0, 12.1.5, 11.6.3.3, 11.5.7

Opened: May 10, 2017

Severity: 3-Major

Symptoms

Qkview captures Kerberos keytab files used for APM dataplane services.

Impact

Private security key exposure.

Conditions

APM provisioned with Kerberos authentication.

Workaround

There is no workaround.

Fix Information

Qkview no longer collects 'kerberos_keytab_file_d' directory containing keytab files when creating qkview archive.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips