Bug ID 1952729: Certificates with explicitly defined EC parameters are treated as invalid in Common Criteria mode and TLS communication will be rejected.

Last Modified: Oct 09, 2025

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
17.5.0, 17.5.1

Fixed In:
17.5.1.2

Opened: May 20, 2025

Severity: 3-Major

Symptoms

In Common Criteria mode, BIG-IP accepts certificates with explicit EC parameters

Impact

In Common Criteria mode, BIG-IP accepts certificates with explicit EC parameters and TLS connection is successful.

Conditions

1. BIG-IP is in Common Criteria (Common Criteria) mode 2. BIG-IP has ECC certificates as a Server and/or Clients/Servers interacting with BIG-IP sending ECC certificates with Explicit EC params.

Workaround

None

Fix Information

Added fix to reject certificates with explicit defined EC params by BIG-IP.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips