Bug ID 885785: Clicking 'Fix Automatically' in PCI Compliance page does not attach a PCI-compliant-profile on HTTP/2 virtual servers

Last Modified: Jan 06, 2023

Bug Tracker

Affected Product:  See more info
BIG-IP ASM(all modules)

Known Affected Versions:
15.1.0,,,,,, 15.1.1, 15.1.2,, 15.1.3,, 15.1.4,, 15.1.5,, 15.1.6,, 15.1.7, 15.1.8,, 16.0.0,, 16.0.1,,

Fixed In:

Opened: Feb 27, 2020
Severity: 4-Minor


For an HTTP/2 virtual server with an insecure client SSL profile attached, clicking the 'Fix Automatically' button on the PCI Compliance page creates a PCI-compliant client SSL profile, but fails to attach to the virtual server. The compliance state shows as a red cross mark, indicating the virtual server to be noncompliant.


The provision for enhanced configuring does not function as expected for HTTP/2-based virtual servers.


-- No compliant PCI profile is attached to the HTTP/2 virtual server. -- Click the 'Fix Automatically' button on the PCI Compliance page.


Manually configure a PCI-compliant profile in SSL profiles, with renegotiation disabled, and attach it to the virtual server.

Fix Information

HTTP/2 virtual servers are now handled correctly in the PCI Compliance page.

Behavior Change