Bug ID 1825949: [APM][Radius] Message-Authenticator value is incorrect for OTP request

Last Modified: Mar 25, 2025

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
17.1.2, 17.1.2.1

Opened: Mar 03, 2025

Severity: 2-Critical

Symptoms

When a OTP challenge is requested on RSA, the Message-Authenticator value in the second request is not corrected/alarmed by the RSA server. Eventually the packet is dropped at the Radius Server.

Impact

This causes authentication failures, disrupting the user’s access control process.

Conditions

The Message-Authenticator attribute radius.messageauthenticator is set to true.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips