Bug ID 867621: FQDN changing based on location

Last Modified: Jul 23, 2021

Bug Tracker

Affected Product:  See more info
BIG-IP APM(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 13.1.4.1, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 15.1.3.1, 16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1, 16.0.1.2, 16.1.0

Opened: Jan 08, 2020
Severity: 3-Major

Symptoms

The macOS hostname is getting changed based on FQDN when On-Demand Cert is specified for macOS clients. The system reports an error: info apmd[13233]: 01490125:6: /REMOTE_ACCESS/SECUREVPN: Client response for the machine cert request: invalid request format

Impact

There is no login page. The message 'Your session could not be established.' is posted instead. Login fails. Cannot use machine cert check to authenticate macOS clients.

Conditions

-- On-Demand Cert is specified for macOS-configured APM clients. -- An APM client on a macOS-based system attempts to log in.

Workaround

Open appropriate Machine Cert Auth VPE item and set the following options: -- Set 'Match subject CN with FQDN' to No. -- Leave 'Match subject Alt Name with FQDN' empty.

Fix Information

None

Behavior Change