Identity And Access
604 incident problems about Identity And Access. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (604)
SECURITY-1261JWT verification breaks after key rotationSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced18 minProSECURITY-1266JWT verification breaks after key rotationA planned key rotation is executed cleanly and one application still begins rejecting newly signed tokens.SecurityAdvanced18 minProSECURITY-1258mTLS appears configured correctly but some clients still failOne client library connects to a service successfully while another fails with trust errors against the same endpoint.SecurityAdvanced18 minProSECURITY-1214CSP looks right but federated login popup still failsA CSP hardening change seems safe until popup or embedded identity flows start failing for some users.SecurityAdvanced19 minProSECURITY-1243mTLS appears correct but one client still failsOne runtime image connects successfully while another fails mTLS against the same upstream even though both trust the same root.SecurityAdvanced19 minProSECURITY-1233mTLS looks configured correctly but one client still failsOne client image connects successfully while another fails to complete the mutual TLS handshake against the same service.SecurityAdvanced19 minProSECURITY-1253mTLS looks correct but one client still failsOne runtime image connects successfully while another fails against the same upstream despite sharing the same root trust.SecurityAdvanced19 minProSECURITY-1248mTLS looks correct on paper but one client still failsOne client runtime connects successfully while another fails against the same upstream despite using the same trusted root set.SecurityAdvanced19 minProSECURITY-1228mTLS trust looks correct but one client still failsA service-to-service connection works from one client image and fails from another despite apparently identical certificates.SecurityAdvanced19 minProSECURITY-1216Secure cookie and redirect settings look correct but one browser still loopsFederated login works in one hostname path but another branded hostname falls into a redirect loop after successful auth.SecurityAdvanced19 minProSECURITY-1213Brute-force detection looks quietA login surface sits behind multiple proxies and the detection pipeline treats one forwarded header as authoritative.SecurityAdvanced20 minProSECURITY-1211Federated login breaks only on callbackAn OIDC flow still reaches the provider successfully, but the callback handler rejects the return due to missing browser state.SecurityAdvanced21 minProSECURITY-1598A PAM radius fallback is fixed and one host still denies usersOne host still denies users after PAM radius fallback fixes.SecurityAdvanced8 minProSECURITY-1564A secret rotation is complete and one workload still reads the old valueOne workload keeps reading the old secret after a successful rotation.SecurityIntermediate8 minProSECURITY-1594An External Secrets fix lands and one app still gets the old payloadOne app still gets the old payload after an External Secrets fix.SecurityIntermediate8 minProSECURITY-1584An External Secrets merge order is fixed and one app still sees the old payloadOne app still sees the old secret payload after merge-order fixes.SecurityIntermediate8 minProSECURITY-1574An External Secrets merge rule is corrected and one workload still builds the old payloadOne workload still assembles the old secret payload after merge-rule cleanup.SecurityIntermediate8 minProSECURITY-1606A JWKS endpoint fix is correct and one verifier still rejects tokensOne verifier still rejects tokens after a JWKS endpoint fix.SecurityAdvanced9 minProSECURITY-1588A RADIUS failover works and one PAM stack still denies valid usersOne PAM stack still denies valid users during RADIUS failover.SecurityAdvanced9 minProSECURITY-1554A secret rotation completes and one workload still uses the retired valueOne workload keeps using a retired secret after rotation across stores.SecurityIntermediate9 minPro