Bug ID 762385: Wrong remote-role assigned using LDAP authentication after upgrade to 14.1.x and later

Last Modified: Dec 15, 2020

Bug Tracker

Affected Product:  See more info
BIG-IP Install/Upgrade, TMOS(all modules)

Known Affected Versions:
14.1.0,,,,,, 14.1.2,,, 15.0.0, 15.0.1,,,,

Fixed In:

Opened: Mar 20, 2019
Severity: 2-Critical


When multiple attributes in a list match multiple roles, the wrong role may be assigned. Alternatively, authentication may fail when check-roles-group is disabled.


BIG-IP assigns the user to the last attribute in the list that matches a role, potentially yielding a more restrictive set of permissions. Authentication may fail when check-roles-group is disabled.


LDAP server replies with a list of attributes (e.g., list of memberOf) where more than one match existing role.



Fix Information

The correct remote-role is now assigned using LDAP authentication.

Behavior Change