Bug ID 708448: Modify LTM client SSL or server SSL profile ciphers default-value does not work

Last Modified: Jan 20, 2023

BIG-IP TMOS(all modules)

Known Affected Versions:
13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0,,,,,,,,, 13.1.1,,,,, 13.1.3,,,,,,, 13.1.4,, 13.1.5,, 14.0.0,,,,,, 14.0.1,, 14.1.0,,,,,, 14.1.2,,,,,,,,, 14.1.3,, 14.1.4,,,,,,, 14.1.5,,,, 15.0.0, 15.0.1,,,,, 15.1.0,,,,,, 15.1.1, 15.1.2,, 15.1.3,, 15.1.4,, 15.1.5,, 15.1.6,, 15.1.7, 15.1.8,, 16.0.0,, 16.0.1,,, 16.1.0, 16.1.1, 16.1.2,,, 16.1.3,,,

Opened: Mar 01, 2018
Severity: 3-Major


The value 'default-value for the ciphers attribute of client SSL or server SSL profiles does not set the ciphers attribute to inherited-from-parent, but instead copies the parent profile's current value. Additionally, it does not set the ciphers attribute to inherited if the attribute had previously been customized.


Any subsequent changes to the parent profile's ciphers value are not inherited by the child profile because the ciphers attribute is considered to be customized, and has not been reset to inherited.


1. Create a child client SSL or server SSL profile. 2. Customize the child profile's ciphers value. 3. Modify the child profile's ciphers value via TMSH to 'default-value'


Any of the following workarounds work: 1. Simultaneously set both 'cipher-group' and 'ciphers' to 'default-value': tmsh modify ltm profile client-ssl child_clientssl cipher-group default-value ciphers default-value 2. In the Configuration Utility, uncheck the customization box for the ciphers attribute on the child profile.

