Bug ID 1584321: OAuth PKCE on MAC edge client when used with OIDC and SPA on Azure

Last Modified: Apr 28, 2025

Affected Product(s):
APM-Clients TMOS(all modules)

Known Affected Versions:
7.2.4.5, 7.2.4.6, 7.2.4.7

Fixed In:
7.2.5, 7.2.4.8

Opened: May 06, 2024

Severity: 3-Major

Symptoms

Edge Client for MAC is not forwarding the bearer token to BIG-IP VPN server. As a result, the BIG-IP access policy is failing with error "Invalid JWS token"

Impact

Authentication fails and Edge Client fails to establish the VPN tunnel

Conditions

-- OAuth PKCE is enabled on Edge Client -- Azure Entra Id is used as the Authorization server with SPA

Workaround

None

Fix Information

Edge client for MAC is now forwarding the bearer token to BIG-IP VPN and BIG-IP access policy will pass.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips