In BIGREST, how to simultaneously add & remove ssl client profile on virtual server?

I am able to add an ssl client profile to a virtual server via

f5_session.create(<span>f"/mgmt/tm/ltm/virtual/</span><span>{</span>rest_format(virtual_server_path_str)<span>}</span><span>/profiles"</span>, data)

I am able to remove an ssl client profile via

delete_path = <span>f"/mgmt/tm/ltm/virtual/</span><span>{</span>rest_format(virtual_server_path_str)<span>}</span><span>/profiles/</span><span>{</span>rest_format(profile_path_str)<span>}</span><span>"<br></span>f5_session.delete(delete_path)

But I need to simultaneously add & delete, because I am replacing the ssl client profile that has “default for SNI” enabled. In order to have exactly one profile with this flag enabled, the add & remove must both occur atomically. I’ve tried every variation I can think of, using `modify()` or `save()`, but still haven’t got it right yet. Here is my latest attempt:

virtual_server_results = f5_session.load(<span>"/mgmt/tm/ltm/virtual"</span>)<br>client_ssl_profile_results = f5_session.load(<span>"/mgmt/tm/ltm/profile/client-ssl"</span>)<br><br>remove_client_ssl_profile = <span>None  # Start as None<br></span>append_client_ssl_profile = <span>None<br></span><span><br></span><span>for </span>client_ssl_profile <span>in </span>client_ssl_profile_results:<br>    <span>if </span>client_ssl_profile.properties[<span>'fullPath'</span>] == <span>'/Common/ssl_client_profile_SNI_1'</span>:<br>        <span>assert </span>remove_client_ssl_profile <span>is None  # Guarantees I cannot set it more than once<br></span>        remove_client_ssl_profile = client_ssl_profile<br>    <span>if </span>client_ssl_profile.properties[<span>'fullPath'</span>] == <span>'/Common/ssl_client_profile_SNI_2'</span>:<br>        <span>assert </span>append_client_ssl_profile <span>is None<br></span>        append_client_ssl_profile = client_ssl_profile<br><br><span>assert </span>remove_client_ssl_profile <span>is not None  # Guarantees I set it at least once<br></span><span>assert </span>append_client_ssl_profile <span>is not None<br></span><span><br># Since `remove_client_ssl_profile` and `append_client_ssl_profile` started as None,<br># and I have `assert remove_client_ssl_profile is None` guaranteeing it will never be set<br># more than once, and I have `assert remove_client_ssl_profile is not None` guaratneeing it<br># was set at least once, I am guaranteed to have found exactly one match for each.<br># No more, no less.<br><br></span><span>for </span>virtual_server <span>in </span>virtual_server_results:<br>    <span># `profilesReference / link` always has the form:<br></span><span>    # 'https://localhost/mgmt/tm/ltm/virtual/~Common~LDAP-Intermediate/profiles?ver=14.1.4.6'<br></span><span>    # So strip the leading 'https://localhost' from it<br></span>    strip_len = <span>len</span>(<span>'https://localhost'</span>)<br>    v_s_profiles_link = virtual_server.properties[<span>"profilesReference"</span>][<span>'link'</span>][strip_len:]<br>    v_s_profiles = f5_session.load(v_s_profiles_link)<br>    <span>for </span>v_s_profile <span>in </span>v_s_profiles:<br>        <span>if </span>v_s_profile.properties[<span>'fullPath'</span>] == remove_client_ssl_profile.properties[<span>'fullPath'</span>]:<br>            v_s_profiles.remove(v_s_profile)<br>            v_s_profiles.append(append_client_ssl_profile)<br>            f5_session.save(virtual_server)

This latest attempt doesn’t throw any errors, but the virtual server doesn’t get changed, so it’s not working.

Thanks for any help.

Why remove and append are none ?

Here, I added comments to the code to explain that. But that was never the important part. The important part is to figure out which object I need to modify by which method, in order to make both changes occur in a single operation.

So far, the only solution I can find (so this is what I’m currently coding up) is: I have to actually delete all the ssl profiles from the virtual server, saving the `sniDefault` one for last. Then I have to add them all back in, with the new `sniDefault` one first.