Topic604 problems· 5 reviewed

Identity And Access

604 incident problems about Identity And Access. Start with the reviewed ones.

All problems (604)

SECURITY-1364An auth_request chain protects the browser UI and one API path bypasses policyA reverse proxy centralizes auth and later only API clients find a path that avoids the expected policy check.SecurityIntermediate12 minProLINUX-1510An MFA rollout validates and one bastion still skips promptsA single bastion host skips MFA after a fleet-wide PAM rollout.LinuxAdvanced12 minProLINUX-1520An MFA rollout validates and one bastion still skips promptsA single bastion skips MFA after the fleet-wide rollout.LinuxAdvanced12 minProSECURITY-1354An NGINX auth_request policy protects the browser UI and one API route...An NGINX auth_request policy protects the browser UI and one API route... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Auth bypasses often hide in alternate method paths the happy-path browser flow never...SecurityIntermediate12 minProSECURITY-1402An RBAC mapper reads the IdP claim and drops every admin groupAn RBAC mapper reads the IdP claim and drops every admin group focuses on Identity And Access and asks the reader to isolate the key signal in okta. Authorization bugs often come from token shape drift rather than token content disapp...SecurityIntermediate12 minProNETWORK-1378Cloudflare Access works on the primary app and the internal admin path loses...Cloudflare Access works on the primary app and the internal admin path... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity propagation can break at internal proxy hops even when the edge...NetworkIntermediate12 minProLINUX-1428SSH certificate auth fails (authorizedprincipalscommand-returned-utf16-encoded-output)SSH certificate auth fails (authorizedprincipalscommand-returned-utf16... focuses on Identity And Access and asks the reader to isolate the key signal in ubuntu. Invisible encoding differences can break SSH auth flows that otherwise l...LinuxAdvanced12 minProLINUX-1438SSH certificate auth fails (authorizedprincipalscommand-returned-utf16-principal-list)SSH certificate auth fails (authorizedprincipalscommand-returned-utf16... focuses on Identity And Access and asks the reader to isolate the key signal in ubuntu. Invisible encoding changes can break SSH auth despite human-readable log...LinuxAdvanced12 minProLINUX-1418SSH certificate login fails only (authorizedprincipalscommand-returned-bom-prefixed-output)SSH certificate login fails only (authorizedprincipalscommand-returned-bom... focuses on Identity And Access and asks the reader to isolate the key signal in ubuntu. Invisible encoding bytes can break SSH auth decisions even when logs...LinuxAdvanced12 minProLINUX-1388A bastion host enforces SSH certificates and one host rejects all valid...A bastion host enforces SSH certificates and one host rejects all valid... focuses on Identity And Access and asks the reader to isolate the key signal in Linux. Time-step issues can masquerade as certificate or CA failures in SSH certif...LinuxAdvanced13 minProNETWORK-1368A Cloudflare Access app authenticates correctly and one admin route still...A Cloudflare Access app authenticates correctly and one admin route still... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity headers often disappear inside the origin proxy long after e...NetworkIntermediate13 minProLINUX-1452A Kerberos service starts rejecting tickets after a chrony migrationAuthentication fails only on hosts moved to a different chrony source after a time-service migration.LinuxAdvanced13 minProNETWORK-1346A Netgate HA pair fails over cleanly and one package VPN stays downAn HA firewall upgrade is validated by failover tests and later one VPN tunnel fails only on the secondary node.NetworkIntermediate13 minProLINUX-1330A package reinstall restores the binary and SELinux still denies executionA recovery action reinstalls a package and afterward one service cannot execute a script or binary that used to work before the incident.LinuxIntermediate13 minProCICD-1345A remote Terraform plan succeeds and one module source keeps failingA remote Terraform plan succeeds and one module source keeps failing focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Remote runners can be correctly authenticated for one Git transport an...CI/CDIntermediate13 minProCICD-1355A remote Terraform run fetches modules and fails provider authA remote Terraform run fetches modules and fails provider auth focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Remote execution often fails on credential source precedence, not on missing cre...CI/CDIntermediate13 minProCICD-1375A remote Terraform run fetches modules and still fails provider authA remote Terraform run fetches modules and still fails provider auth focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Remote execution often fails on credential-source precedence rather than on mi...CI/CDIntermediate13 minProSECURITY-1344An NGINX auth_request chain protects the UI and one API path still bypasses policyA reverse proxy centralizes auth and later only API clients or browser preflight flows can reach one path without the expected policy check.SecurityIntermediate13 minProSECURITY-1333An NGINX auth_request chain works for browsers and fails for API clientsAn NGINX auth_request chain works for browsers and fails for API clients focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Authentication success at the edge does not preserve every authorization s...SecurityIntermediate13 minProSECURITY-1307An OIDC mobile deep link works in test and fails in productionA mobile auth flow works in staging and later fails only in production after app-registration values were copied manually.SecurityIntermediate13 minPro