Symptom164 problems· 12 reviewed

Auth and Session Failure

164 incident problems that show up as “Auth and Session Failure”.

All problems (164)

SECURITY-036IMDSv1 remains reachable on a standby node after hardening rolloutPrimary instances were hardened correctly, but a rarely used standby or replacement path still exposes the older metadata service behavior.SecurityIntermediate18 minFreeSECURITY-073mTLS client authentication failsThe certificate is valid and trusted, but client auth still fails because the service enforces a SAN type that the issued cert never included.SecurityIntermediate18 minFreeSECURITY-010Password policy update breaks automation account loginA stronger policy is applied broadly, but one unattended account still uses the old credential pattern and starts failing.SecurityBeginner13 minFreeLINUX-084sudo NOPASSWD rule is present but a later group rule still forces password promptsThe expected privilege rule exists, but one broader matching policy lower in the evaluation path overrides the operator's assumption about effective behavior.LinuxIntermediate13 minFreeSECURITY-007Fail2ban blocks internal health checks after noisy auth failuresA brute-force defense rule works, but its source grouping catches internal monitoring traffic by mistake.SecurityBeginner15 minFreeLINUX-086sshd Match block for a bastion subnet disables agent forwarding on one host class onlySSH works broadly, but a specific bastion path behaves differently because a later Match clause quietly changes capabilities for one source range.LinuxIntermediate15 minFreeNETWORK-094VLAN exists on both switches but VTP pruning removes the path users think is activeThe database is correct, yet traffic still disappears because dynamic pruning removed the VLAN from a trunk users assumed was always carrying it.NetworkIntermediate15 minFreeNETWORK-082Access switch uplink looks up but the native VLAN changed and voice phones never get the right DHCP scopeLink status is healthy, yet phone onboarding fails because the expected voice and management traffic classification changed with the trunk native VLAN baseline.NetworkIntermediate16 minFreeNETWORK-098Stack member replacement keeps the config but loses the DHCP snooping binding table after reloadUser traffic recovers briefly, then fails after reload because the new member does not retain the dynamic trust state the design relied on.NetworkIntermediate16 minFreeSECURITY-035Identity provider session expires before a long-running admin workflow finishesThe user signs in successfully and starts a privileged operation, but the background confirmation step fails because the IdP session duration is shorter than the workflow window.SecurityBeginner17 minFreeLINUX-070SSSD cache preserves deleted group membership and sudo access lingers after offboardingThe identity source is already updated, but one host still grants privileged access because its local cache did not expire when the account changed.LinuxIntermediate17 minFreeNETWORK-070DHCP snooping uplink trust is missing after a switch replacement and clients lose gateway accessAccess ports still look normal, but ARP and DHCP behavior collapses because the new switch never restored the trusted uplink role toward the real infrastructure path.NetworkIntermediate18 minFreeSECURITY-061SAML login fails after an IdP migrationThe IdP is reachable and the assertion is signed, but the application still rejects login because the expected identity field changed during the migration.SecurityIntermediate18 minFreeSECURITY-054SIEM parser timezone drift shifts the incident timeline by several hoursThe raw logs are present, but correlation and response decisions go wrong because one pipeline normalizes timestamps differently from the rest of the stack.SecurityIntermediate19 minFreeSECURITY-019Nginx basic auth protects one path but leaves upload endpoint openNginx basic auth protects one path but leaves upload endpoint open is a hands-on troubleshooting drill. The visible admin page is protected, but an adjacent upload route bypasses the same security control. NGINX Identity and Access Management needs to be checked by narrowing s...SecurityBeginner13 minFreeLINUX-024File exists but service user cannot follow parent directoryFile exists but service user cannot follow parent directory is a hands-on troubleshooting drill. The file permission looks fine, but one directory in the path denies execute permission and breaks access. Azure Linux Service Operations needs to be checked by narrowing scope, re...LinuxBeginner14 minFreeLINUX-038Sudoers drop-in order silently reintroduces password promptsThe main sudoers file looks correct, but a later drop-in overrides the intended NOPASSWD rule and breaks the automation path.LinuxBeginner14 minFreeLINUX-021Cron job runs manually but fails under non-login shellCron job runs manually but fails (404 and Rewrite Mismatch) is a hands-on troubleshooting drill. The command succeeds interactively but breaks in cron because environment setup and path assumptions are missing. Azure Linux Service Operations needs to be checked by narrowing sc...LinuxBeginner15 minFreeNETWORK-061DHCP relay helper is missing on the new SVI and only remote VLAN clients lose leasesLocal hosts work normally, but one moved VLAN never gets addresses because the relay path was not recreated on the replacement interface.NetworkBeginner15 minFreeK8S-024Pod restartsThe file exists and the volume is mounted, but the runtime user cannot read the config because the mode is too strict.KubernetesBeginner15 minFree