Identity and Access Management
87 incident problems about Identity and Access Management. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (87)
SECURITY-012Token validation passes in app tier but fails in background queueToken validation passes in app tier but fails in background queue is a hands-on troubleshooting drill. A queue consumer uses a different issuer or clock setting and rejects tokens that looked valid at the edge. Identity and Access Management needs to be checked by narrowing sc...SecurityAdvanced26 minProSECURITY-151A passkey login works on the primary domain, but a support subdomain still advertises the old RP ID and users cannot recover sessions therePasswordless auth is partially deployed, leaving one operational path outside the trust boundary.SecurityAdvanced16 minProSECURITY-127An SSH CA signs the right principal, but a restrictive source-address critical option excludes the bastion's NAT rangeCertificate auth looks correct until network translation changes the apparent client source.SecurityAdvanced16 minProSECURITY-112WebAuthn enrollment succeeds, but the stored rpId still points at the old domain after a production cutoverUsers can register credentials, yet sign-in later fails because the relying party identity was not updated with the new canonical hostname.SecurityAdvanced17 minProSECURITY-017Session cookie becomes insecure after CDN to origin scheme mismatchUsers arrive over HTTPS, but origin headers make the app think the request is plain HTTP and weaken the session cookie flags.SecurityIntermediate20 minProSECURITY-023API key restriction by source IP breaks autoscaled workersThe restriction was safe at one size, but autoscaling introduces new egress addresses that were never added to the policy.SecurityIntermediate21 minProSECURITY-029OAuth callback accepted on web tier but rejected after load balancer hopOAuth callback accepted on web tier but rejected is a hands-on troubleshooting drill. The callback parameters are correct, yet one load balancer rewrite alters the host or scheme expected by validation. Identity and Access Management needs to be checked by narrowing scope, rec...SecurityIntermediate22 minPro