Bug ID 685310: Adding/reimport device to an Access Group

Last Modified: Oct 10, 2018

Bug Tracker

Affected Product:  See more info
BIG-IQ 1UX Config - Access(all modules)

Known Affected Versions:
5.4.0, 5.4.0 HF1, 5.4.0 HF2

Opened: Sep 25, 2017
Severity: 3-Major

Symptoms

After adding a device or reimporting a device-specific configuration to a BIG-IQ Access Group, any Kerberos object for the added or reimported device must be manually fixed by uploading an appropriate keytab file object. By default, it uses the object from the source device.

Impact

Kerberos might use the wrong keytab file from source-device on BIG-IP after deployment. This may result in Kerberos authentication failure.

Conditions

All Kerberos LSO device instances in BIG-IQ use the same keytab file as the source device after adding a device or reimporting a device-specific configuration from the device.

Workaround

Upload the keytab file in BIG-IQ for each Kerberos object and deploy.

Fix Information

None

Behavior Change