Topic604 problems· 5 reviewed

Identity And Access

604 incident problems about Identity And Access. Start with the reviewed ones.

All problems (604)

SECURITY-1487A SAML assertion validates and browser login still failsSAML login works in test tools and fails in browsers after a callback hostname migration.SecurityIntermediate10 minProSECURITY-1496A SAML metadata refresh succeeds and SP-initiated login still loopsSP-initiated SAML login loops only for one realm after an IdP metadata and signing cert refresh.SecurityIntermediate10 minProSECURITY-1506A SAML metadata refresh succeeds and SP-initiated login still loopsSP-initiated SAML login loops only for one realm after metadata refresh.SecurityIntermediate10 minProSECURITY-1516A SAML metadata refresh succeeds and SP-initiated login still loopsSP-initiated SAML login loops only for one realm after metadata refresh.SecurityIntermediate10 minProSECURITY-1476A SAML response validates and still fails only in browsersSAML login works in test tools and fails in browsers only after cookie defaults change on the callback domain.SecurityIntermediate10 minProCICD-1598A Vault injector policy is corrected and one deployment still uses the old namespace pathOne deployment still reads the old Vault namespace path after injector fixes.CI/CDAdvanced10 minProCICD-1608A Vault injector policy is updated and one deployment still reads the old pathOne deployment still reads the old Vault path after injector updates.CI/CDAdvanced10 minProSECURITY-1472An OpenSearch authz fix is deployed and one tenant still gets deniedAccess remains broken for one tenant only on requests that land on a recently relocated shard path.SecurityIntermediate10 minProSECURITY-1462An OpenSearch role mapping update applies cleanly and one tenant still gets 403One tenant loses dashboard access right after an IdP claim mapper cleanup changed role casing.SecurityIntermediate10 minProLINUX-1496A chrony source list is healthy and Kerberos still failsKerberos fails only on recently restored VMs even though chrony reports synchronized sources.LinuxAdvanced11 minProLINUX-1506A chrony source list is healthy and Kerberos still failsKerberos fails only on recently restored VMs even though chrony shows healthy sources.LinuxAdvanced11 minProLINUX-1516A chrony source list is healthy and Kerberos still failsKerberos fails only on VMs restored from snapshot after time policy changes.LinuxAdvanced11 minProLINUX-1526A chrony source list is healthy and Kerberos still failsKerberos fails only on restored VMs after time policy changes.LinuxAdvanced11 minProSECURITY-1395A Prometheus or Alertmanager basic-auth secret rotates and one instance still...A Prometheus or Alertmanager basic-auth secret rotates and one instance... focuses on Identity And Access and asks the reader to isolate the key signal in grafana. Rotation bugs can hide in file rendering and comparison behavio...SecurityIntermediate11 minProCICD-1461A reusable workflow keeps losing OIDC tokensA reusable deployment workflow works in its template repo and fails only when called from the protected production repo.CI/CDIntermediate11 minProSECURITY-1455A SAML response verifies and one ACS path still rejects itSAML login works on one path and fails only behind a proxy that now terminates TLS differently.SecurityIntermediate11 minProNETWORK-1394A TCP stream proxy still passes traffic and client IP allowlists failA TCP stream proxy still passes traffic and client IP allowlists fail focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Source identity failures can come from protocol version mismatch even when tr...NetworkIntermediate11 minProCICD-1568A Vault AppRole secret rotates and one deploy still authenticates with the old roleOne deployment keeps authenticating with an old AppRole after rotation.CI/CDAdvanced11 minProSECURITY-1400A Vault dynamic DB credential works and one app still rejects itDynamic credentials are rolled out and one application alone starts rejecting them despite the DB and Vault role being correct.SecurityIntermediate11 minProCICD-1588A Vault policy change is correct and one deploy still failsOne deployment still fails Vault auth after a CIDR policy change.CI/CDAdvanced11 minPro