Bug ID 1166113: [Mul. Dom SSO] - "?" chars are wrongly encoded, leading connections to fail.

Last Modified: Oct 09, 2025

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
15.1.7, 15.1.8, 17.0.0.1

Fixed In:
17.1.0, 17.0.0.2, 16.1.3.3, 15.1.8.1, 14.1.5.3

Opened: Oct 01, 2022

Severity: 3-Major

Symptoms

After successful authn to MultiDomain SSO [MD SSO] Primary host, shows the character "?" has been encoded as "%3F".

Impact

Connection fails

Conditions

MultiDomain SSO

Workaround

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ when CLIENT_ACCEPTED { ACCESS::restrict_irule_events disable } when HTTP_REQUEST { set reqTarget 0 if { [HTTP::uri] starts_with "/F5Networks-SSO-Resp" } { log local0. "====> Spotted MD SSO response ..." set reqTarget 1 } } when HTTP_RESPONSE_RELEASE { if { [HTTP::status] == 302 && $reqTarget } { log local0. "====> Spotted HTTP Redirect ..." set originalHeader [HTTP::header "Location"] set newdata [string map {"%3F" "?"} $originalHeader] HTTP::header replace Location $newdata } } ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips