Bug ID 860245: SSL Orchestrator configuration not synchronized across HA-pair after upgrade from 14.1.2.1

Last Modified: Mar 18, 2020

Bug Tracker

Affected Product:  See more info
BIG-IP SSLO(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.4, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.1.0

Opened: Dec 12, 2019
Severity: 1-Blocking

Symptoms

The SSL Orchestrator configuration is not synced properly across the high availability (HA) configuration. The REST framework versions are different on the two devices.

Impact

SSL Orchestrator configuration not syncing across the BIG-IP high availability (HA) pair.

Conditions

-- BIG-IP devices configured in high availability (HA) mode. -- SSL Orchestrator configured. -- Upgrading from v14.1.2 to v15.1.x or newer.

Workaround

The following steps are required on both high availability (HA) peers, first on the active and then on the standby BIG-IP device. 1. Open a terminal session with admin/root level access. 2. Run the following commands, in the order specified: bigstart stop restjavad rm -rf /shared/em/ssl.crt/* bigstart start restjavad restcurl -X DELETE shared/resolver/device-groups/tm-shared-allBIG-IPs/devices restcurl -X DELETE shared/gossip-conflicts restcurl -X DELETE shared/device-certificates restcurl -X POST -d '{"generateKeyPair": true}' shared/device-key-pair bigstart restart restjavad restnoded

Fix Information

None

Behavior Change