Bug ID 762385: After upgrade to 14.1 wrong remote-role assigned using LDAP authentication

Last Modified: Jun 13, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP Install/Upgrade, TMOS(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.4, 14.1.0.5, 14.1.0.6, 15.0.0

Opened: Mar 20, 2019
Severity: 2-Critical

Symptoms

When multiple attributes in a list match multiple roles, the wrong role may be assigned. Alternatively, authentication may fail when check-roles-group is disabled.

Impact

BIG-IP assigns the user to the last attribute in the list that matches a role yielding more restrictive set of permissions. Authentication may fail when check-roles-group is disabled.

Conditions

LDAP server replies with a list of attributes (e.g., list of memberOf) where more than one match existing role.

Workaround

None

Fix Information

None

Behavior Change