While I was configuring and testing an APM Access policy for an OIDC integration with Entra ID, I was seeing some backchannel errors logged (debug level) some HTTP error 400.
The whole logging is quite verbose, but here, not very useful:
<br>[...]<br>OAuth Client: failed for server '/Common/entraid_test' using 'authorization_code' grant type (client_id=xxxxxxxxxxxxxx), error: HTTP error 400,<br><br>Session variable 'session.oauth.client./Common/entra_front_act_oauth_client_ag.errMsg' set to 'HTTP error 400, '<br><br>Session variable 'session.oauth.client./Common/entraid_test.errMsg' set to 'HTTP error 400, '<br><br>Session variable 'session.oauth.client.last.errMsg' set to 'HTTP error 400, '
So, tcpdump was required to see what exactly the error was in the returned JSON payload from Entra ID.
I’ve got a new RFE from F5 support =>
(Bug alias 2229965) [RFE] Add extra verbosity for the debug-level logging for OIDC backchannel connection
Don’t hesitate to open a support case to get it bound to that RFE, the more we are the higher priority will be assigned to implement it (hopefully). ![]()
Alexandre