Forum Discussion
MrVJTod_64267
Nimbostratus
Jan 25, 2018SSL certs reset to default on 12.1.3 with client profile change
Since I updated all of my boxes to 12.1.3, I've realized that SSL certificates are dropped from my SSL profiles each time I make a change to an SSL Client profile.
If I modify the ciphers or ena...
Hannes_Rapp
Nimbostratus
Jan 27, 2018This seems very familiar. It can be fixed permanently with a one-time effort.
During software upgrade, boolean value of
inherit-certkeychain of your custom clientssl profiles may get tampered. Last time I upgraded, this bug only affected custom clientssl profiles where one or more settings were derived from another custom clientssl profile. In my experience, this bug has never affected custom clientssl profiles that only inherit settings from the system-default clientssl profile.
Fix:
- Take raw backup of current bigip.conf file:
cp /config/bigip.conf /var/tmp/bigip.conf.bak - Open up
with vi or alternative, and search for/config/bigip.conf
keyword occurrences. For every custom clientssl profile that should use their own dedicated certificate/key pairs, replace configuration line that saysinherit-certkeychain
withinherit-certkeychain true
. (If the broken profile does not have inherit-certkeychain line in it's configuration, then add it yourself and make sure it's value is "false")inherit-certkeychain false - Save changes to /config/bigip.conf and load in new configuration to TMOS with
.tmsh load sys config
Now you can implement changes to your clientssl profiles via GUI normally.
Note: This can be implemented on a live production system with no negative impact. But there's substantial risk of messing up configuration. Do your own due diligence during low activity hours with just 1 profile, or ideally test everything in a testing environment.
Regards,
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
