Bug ID 1779921: "Apply Access Policy" Status stays yellow for Access profiles using OAuth agent with "Dynamic Server" enabled during key updates in OAuth auto-discovery

Last Modified: Jun 19, 2025

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
17.1.1.3, 17.1.1.4, 17.1.2, 17.1.2.1, 17.1.2.2

Opened: Dec 24, 2024

Severity: 3-Major

Symptoms

Newly discovered keys are not updated to access profiles with "dynamic server" enabled. As a result, they will be using older keys.

Impact

-- When you apply the access policy, the status remains yellow. -- OAuth fails as the access profile still uses the old keys.

Conditions

-- BIG-IP HA pair -- BIG-IP system is configured as a OAuth client/Resource server -- Access profile has OAuth agent(OAuth client/OAuth scope) with "dynamic server" enabled -- Keys are updated on the OAuth authorization server which will be discovered on the OAuth client during discovery task

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips