Bug ID 2197305: BIG-IP generates invalid SSL key share

Last Modified: Jan 16, 2026

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
17.1.3

Opened: Dec 30, 2025

Severity: 3-Major

Symptoms

SSL handshakes fail on the client due to an Illegal Parameter alert.

Impact

SSL handshake fails and the connection terminates

Conditions

ClientSSL that mixes both FFDHE and Non-FFDHE groups and has session tickets enabled. The client tries to resume an SSL session with a Non-FFDHE key share that used FFDHE previously.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips