Secondary DNS resolver console had no single sign-on
The failover DNS resolver's web console was reachable without the sign-on gate that protects the primary one.
The deployment template that wires an application into single sign-on had been applied for only one of the two resolver hostnames. The sign-on rules for the second host were never created at all, so requests to it bypassed the gate entirely rather than failing closed.
Cause. The sign-on importer processes its entries strictly top to bottom, and a reference can only resolve to an object that already exists earlier in the same file. The gateway entry was ordered ahead of the second host's rules, so the import — which is atomic — could never attach them.
Fix. Both hostnames' rules now precede the gateway entry in the template. Verified live: both hostnames return a redirect to the sign-on page, and the gateway reports the import as successful.
0 Comments
Sign in to comment
No comments yet. Be the first to share your thoughts!
