I am able to add an ssl client profile to a virtual server via
f5_session.create(<span>f"/mgmt/tm/ltm/virtual/</span><span>{</span>rest_format(virtual_server_path_str)<span>}</span><span>/profiles"</span>, data)
I am able to remove an ssl client profile via
delete_path = <span>f"/mgmt/tm/ltm/virtual/</span><span>{</span>rest_format(virtual_server_path_str)<span>}</span><span>/profiles/</span><span>{</span>rest_format(profile_path_str)<span>}</span><span>"<br></span>f5_session.delete(delete_path)
But I need to simultaneously add & delete, because I am replacing the ssl client profile that has “default for SNI” enabled. In order to have exactly one profile with this flag enabled, the add & remove must both occur atomically. I’ve tried every variation I can think of, using `modify()` or `save()`, but still haven’t got it right yet. Here is my latest attempt:
virtual_server_results = f5_session.load(<span>"/mgmt/tm/ltm/virtual"</span>)<br>client_ssl_profile_results = f5_session.load(<span>"/mgmt/tm/ltm/profile/client-ssl"</span>)<br><br>remove_client_ssl_profile = <span>None # Start as None<br></span>append_client_ssl_profile = <span>None<br></span><span><br></span><span>for </span>client_ssl_profile <span>in </span>client_ssl_profile_results:<br> <span>if </span>client_ssl_profile.properties[<span>'fullPath'</span>] == <span>'/Common/ssl_client_profile_SNI_1'</span>:<br> <span>assert </span>remove_client_ssl_profile <span>is None # Guarantees I cannot set it more than once<br></span> remove_client_ssl_profile = client_ssl_profile<br> <span>if </span>client_ssl_profile.properties[<span>'fullPath'</span>] == <span>'/Common/ssl_client_profile_SNI_2'</span>:<br> <span>assert </span>append_client_ssl_profile <span>is None<br></span> append_client_ssl_profile = client_ssl_profile<br><br><span>assert </span>remove_client_ssl_profile <span>is not None # Guarantees I set it at least once<br></span><span>assert </span>append_client_ssl_profile <span>is not None<br></span><span><br># Since `remove_client_ssl_profile` and `append_client_ssl_profile` started as None,<br># and I have `assert remove_client_ssl_profile is None` guaranteeing it will never be set<br># more than once, and I have `assert remove_client_ssl_profile is not None` guaratneeing it<br># was set at least once, I am guaranteed to have found exactly one match for each.<br># No more, no less.<br><br></span><span>for </span>virtual_server <span>in </span>virtual_server_results:<br> <span># `profilesReference / link` always has the form:<br></span><span> # 'https://localhost/mgmt/tm/ltm/virtual/~Common~LDAP-Intermediate/profiles?ver=14.1.4.6'<br></span><span> # So strip the leading 'https://localhost' from it<br></span> strip_len = <span>len</span>(<span>'https://localhost'</span>)<br> v_s_profiles_link = virtual_server.properties[<span>"profilesReference"</span>][<span>'link'</span>][strip_len:]<br> v_s_profiles = f5_session.load(v_s_profiles_link)<br> <span>for </span>v_s_profile <span>in </span>v_s_profiles:<br> <span>if </span>v_s_profile.properties[<span>'fullPath'</span>] == remove_client_ssl_profile.properties[<span>'fullPath'</span>]:<br> v_s_profiles.remove(v_s_profile)<br> v_s_profiles.append(append_client_ssl_profile)<br> f5_session.save(virtual_server)
This latest attempt doesn’t throw any errors, but the virtual server doesn’t get changed, so it’s not working.
Thanks for any help.