Loading...
Loading...
When using ClientCert-LDAP (CAC certificate) authentication, some users intermittently fail to log in to the BIG-IP GUI or SSH. Not all users are affected; only a subset of users whose certificates are issued from certain Certificate Authorities experience the failure. Other users with the same ClientCert-LDAP configuration can log in successfully.
Admin users relying on CAC (certificate-based) authentication are unable to log in to the BIG-IP GUI or SSH on affected appliances.
This issue occurs when ALL of the following are true: - BIG-IP is configured for ClientCert-LDAP (CAC certificate) authentication - OCSP verification is enabled for client certificates - The authenticating user's certificate is issued by a CA whose issuer certificate is not available to the OCSP verification chain - The PAM module is configured with ignore_authinfo_unavail
None
None
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.