Bug ID 762385: After upgrade to 14.1 wrong remote-role assigned using LDAP authentication

Last Modified: Oct 14, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP Install/Upgrade, TMOS(all modules)

Known Affected Versions:
14.1.0,,,,,,, 14.1.2,, 15.0.0, 15.0.1

Opened: Mar 20, 2019
Severity: 2-Critical


When multiple attributes in a list match multiple roles, the wrong role may be assigned. Alternatively, authentication may fail when check-roles-group is disabled.


BIG-IP assigns the user to the last attribute in the list that matches a role yielding more restrictive set of permissions. Authentication may fail when check-roles-group is disabled.


LDAP server replies with a list of attributes (e.g., list of memberOf) where more than one match existing role.



Fix Information


Behavior Change