For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

luoye's avatar
luoye
Icon for Nimbostratus rankNimbostratus
Apr 17, 2017

12.1.1 ve modify setting error

Hi,guys: When I modify setting in the web GUI,there are err log "Apr 14 16:18:43 big-ip-1 warning mcpd[6504]: 01071031:4: Security setting systemauth.disablerootlogin has been disabled by user admin Apr 14 16:18:43 big-ip-1 err mcpd[6504]: 01070912:3: unable to open file: /tmp/confpp.dat Apr 14 16:18:43 big-ip-1 err mcpd[6504]: 01070712:3: Caught configuration exception (0), unable to open file: /tmp/confpp.dat. Apr 14 16:18:44 big-ip-1 err tmsh[6310]: 01420006:3: Can't create temp directory, /.config.tmp/yQpX5k, errno 30] Read-only file system"

 

What's more,I input "tmsh" in the CLI,there is a err log"big-ip-1 crit tmsh[6448]: 01420001:2: Can't open command history file (/root/.tmsh-history-root), Read-only file system : framework/CmdHistoryFile.cpp, line 92" Do you have seen this situation?I can't find anything in the askF5.The systmem is 12.1.1 VE.

 

2 Replies

  • It seems one or more partitions are mounted 'read-only' on your BIG-IP. You can check this by running the command 'mount' from bash. Could you show us the output of this command?

     

    Also the output of 'ls -la /' would be interesting, to see how the permissions on the /tmp and /root directory are set.

     

  • luoye's avatar
    luoye
    Icon for Nimbostratus rankNimbostratus

    Hi,friend.How can I find the problem?

     

    [root@big-ip-1:ModuleNotLicensed:Active:Standalone] config mount

     

    /dev/mapper/vg--db--sda-set.1.root on / type ext3 (rw,noatime)

     

    none on /proc type proc (rw)

     

    devpts on /dev/pts type devpts (rw) none on /dev/shm type tmpfs (rw,noatime,rootcontext="system_u:object_r:tmpfs_t:s0")

     

    /dev/mapper/vg--db--sda-set.1._config on /config type ext3 (rw,noatime)

     

    /dev/mapper/vg--db--sda-set.1._usr on /usr type ext3 (ro,noatime)

     

    /dev/mapper/vg--db--sda-set.1._var on /var type ext3 (rw,noexec,noatime)

     

    /dev/mapper/vg--db--sda-dat.share.1 on /shared type ext3 (rw,noatime)

     

    /dev/mapper/vg--db--sda-dat.log.1 on /var/log type ext3 (rw,noatime) none on /shared/rrd.1.2 type tmpfs (rw,noatime,rootcontext="system_u:object_r:file_t:s0") none on /var/tmstat type tmpfs (rw,rootcontext="system_u:object_r:file_t:s0") none on /var/run type tmpfs (rw,noatime,rootcontext="system_u:object_r:file_t:s0") none on /sys/kernel/debug type debugfs (ro,noexec) prompt on /var/prompt type tmpfs (rw,size=4m,rootcontext="system_u:object_r:file_t:s0") none on /proc/sys/fs/binfmt_misc type binfmt_misc (rw) none on /var/loipc type tmpfs (rw,noatime,rootcontext="system_u:object_r:var_t:s0") /var/named/lib on /var/named/lib type none (rw,bind) /dev/mapper/vg--db--sda-app.ASWADB.set.1.mysqldb on /var/lib/mysql type ext3 (rw,noatime) /dev/mapper/vg--db--sda-app.avr.dat.avrdata on /shared/avr type ext3 (rw) none on /dev/mprov/avr type hugetlbfs (rw) none on /dev/mprov/tmm type hugetlbfs (rw)

     

    mount: warning: /etc/mtab is not writable (e.g. read-only filesystem). It's possible that information reported by mount(8) is not up to date. For actual information about system mount points check the /proc/mounts file.

     

    [root@big-ip-1:ModuleNotLicensed:Active:Standalone] config

     

    [root@big-ip-1:ModuleNotLicensed:Active:Standalone] config ls -la /

     

    total 154 dr-xr-xr-x. 28 root root 1024 2017-01-11 16:12 . dr-xr-xr-x. 28 root root 1024 2017-01-11 16:12 .. -rw-r--r--. 1 root root 88 2017-01-11 16:13 1 -rw-r--r--. 1 root root 0 2017-01-11 16:12 .autofsck dr-xr-xr-x. 2 root root 4096 2017-01-10 18:55 bin dr-xr-xr-x. 6 root root 1024 2017-01-10 18:55 boot drwxr-xr-x. 2 root root 1024 2016-08-12 07:35 cgroup drwxr-xr-x. 2 root root 1024 2017-01-10 18:53 command drwxr-xr-x. 23 root root 4096 2017-04-17 15:40 config drwxrwxrwt. 2 root root 1024 2017-03-09 18:42 .config.tmp -r-xr-xr-x. 1 root root 2408 2016-08-12 07:24 CONTACTS -r-xr-xr-x. 1 root root 1100 2016-08-12 07:24 COPYRIGHT lrwxrwxrwx. 1 root root 19 2017-01-10 18:53 defaults -> /usr/share/defaults drwxr-xr-x. 18 root root 3800 2017-01-13 21:17 dev drwxr-xr-x. 102 root root 8192 2017-03-10 10:10 etc lrwxrwxrwx. 1 root root 19 2017-01-10 18:53 examples -> /usr/share/examples drwxr-xr-x. 6 root root 1024 2017-02-21 16:17 home drwxr-xr-x. 2 root root 1024 2016-08-12 07:20 hotfix -rw-r--r--. 1 root root 223 2017-01-11 16:13 HWINFO dr-xr-xr-x. 15 root root 9216 2017-01-10 18:55 lib drwxr-xr-x. 5 root root 8192 2017-01-10 18:53 lib64 drwx------. 2 root root 12288 2017-01-10 18:50 lost+found drwxr-xr-x. 2 root root 1024 2016-08-12 07:32 media drwxr-xr-x. 5 root root 1024 2017-01-11 03:26 mnt drwxr-xr-x. 7 root root 1024 2017-01-10 18:53 opt -rw-r--r--. 1 root root 0 2016-08-12 08:03 .permit.plymouthd -rw-r--r--. 1 root root 55 2017-01-10 11:02 PLATFORM -rw-r--r--. 1 root root 0 2016-08-12 08:03 .plymouthd.show_default_splash dr-xr-xr-x. 318 root root 0 2017-01-11 16:12 proc -rw-------. 1 root root 1024 2017-03-15 15:01 .rnd dr-x------. 3 root root 1024 2017-03-15 15:51 root dr-xr-xr-x. 3 root root 7168 2017-01-10 18:55 sbin drwxr-xr-x. 7 root root 0 2017-01-11 16:12 selinux lrwxrwxrwx. 1 root root 12 2017-01-10 18:53 service -> /var/service drwxr-xr-x. 27 root root 4096 2017-04-17 16:14 shared drwxr-xr-x. 2 root root 1024 2016-08-12 07:32 srv drwxr-xr-x. 13 root root 0 2017-01-11 16:12 sys -rw-r--r--. 1 root root 0 2016-08-12 08:03 .sysinit.run.plymouthd drwxrwxrwt. 5 root root 7168 2017-03-15 03:23 tmp lrwxrwxrwx. 1 root root 7 2017-01-10 18:54 ts -> /var/ts drwxr-xr-x. 18 root root 4096 2017-01-10 18:53 usr -rw-r--r--. 1 root root 0 2017-01-10 18:55 .vadc_fetch_keys drwxr-xr-x. 53 root root 4096 2017-01-11 16:14 var -r-xr-xr-x. 1 root root 1148 2016-08-12 07:24 VENDOR lrwxrwxrwx. 1 root root 11 2017-01-10 18:50 VERSION -> VERSION.LTM -rw-r--r--. 1 root root 0 2016-08-12 07:26 VERSION.ASM -rw-r--r--. 1 root root 197 2017-01-10 18:50 VERSION.LTM -rw-r--r--. 1 root root 25 2016-08-12 08:09 VERSION.WA -rw-r--r--. 1 root root 0 2016-08-12 08:31 VERSION.WOC [root@big-ip-1:ModuleNotLicensed:Active:Standalone] config