Last Modified: Dec 13, 2019
See more info
BIG-IP Install/Upgrade, TMOS
Known Affected Versions:
14.1.0, 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 14.1.2, 184.108.40.206, 220.127.116.11, 15.0.0, 15.0.1
Opened: Mar 20, 2019
When multiple attributes in a list match multiple roles, the wrong role may be assigned. Alternatively, authentication may fail when check-roles-group is disabled.
BIG-IP assigns the user to the last attribute in the list that matches a role, potentially yielding a more restrictive set of permissions. Authentication may fail when check-roles-group is disabled.
LDAP server replies with a list of attributes (e.g., list of memberOf) where more than one match existing role.
The correct remote-role is now assigned using LDAP authentication after upgrade to 15.1.x.