Forum Discussion
biggaraga
Nimbostratus
Jun 04, 2021Authorization Header Defined as Unparsable by F5_ASM
One of our development teams is adding a new OAUTH token feature to an application. Sending the JSON call with the Authorization header creates an error within F5_ASM (ver 15.13): HTTP Validation U...
AlexBCT
Cumulonimbus
Jun 05, 2021Hi,
Any chance that you've run into this bug? https://support.f5.com/csp/article/K67111200
Version 15.1.3 is one of the affected versions
Hope this helps.
biggaraga
Nimbostratus
Jun 07, 2021For clarification, my team has been reading through these:
Disable the Unparsable request content violation
You may disable the Unparsable request content violation in the affected security policies.
Impact of workaround: The BIG-IP will no longer trigger violations for any unparseable content, not specifically limited to Authorization headers.
Enable the 'ignore_authorization_header_decode_failure' internal parameter
Consider enabling this internal parameter to ignore only failures to decode authorization headers, leaving the Unparsable request content violation enabled in the policy.
There’s two options here, and we’re wondering if this is granular to do per policy or if we have to do for all policies. Could you give us clarity?
Thanks
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects