Bug ID 610594: Authorization grant using auth code fails with IE11 when OAuth AS clientssl profile is using untrusted certificate

Last Modified: Jul 12, 2023

Affected Product(s):
BIG-IP APM(all modules)

Fixed In:
13.0.0

Opened: Aug 12, 2016

Severity: 4-Minor

Symptoms

IE11 modifies the HTTP method from GET to POST after certificate warning ERROR_INTERNET_SEC_CERT_ERRORS.

Impact

This behavior fails the protocol and AS responds with invalid_request due to missing response_type in POST body.

Conditions

When IE11 is used in conjunction with BIGIP OAuth Client and OAuth AS clientssl profile is using untrusted certificate.

Workaround

Avoid untrusted certificate in OAuth AS clientssl profile.

Fix Information

Functions as designed.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips