Bug Reports
Complete

Every application behind single sign-on fell into a redirect loop

Overnight on 1 September, every application protected by single sign-on became unreachable. A login attempt bounced between the application and the sign-on service indefinitely; browsers reported that the page was not redirecting properly.

The cause was an unattended update of the sign-on platform. The new release only honours forwarded request headers when the connection arrives from a trusted network. The authentication gateways reach the sign-on service over the public address, so their traffic arrived from an untrusted source, their headers were discarded, and the final step of the login exchange was rejected. Each rejection restarted the login, which is what produced the loop.

Nothing was lost and no credential was exposed. The gateways reported healthy throughout, which is why the fault was not visible from monitoring.

0 Comments

Sign in to comment

No comments yet. Be the first to share your thoughts!