Andrew Wood
Articles
-
Enforce Password Change and Minimum Password Age
Version Affected: 20.06+ Description: From 20.06 HF11 onwards, we introduced a fix to prevent Users from bypassing the minimum password age setting in AD. Prior to this, the Enforce Password ch...
-
How to increase the allowed clock skew for API calls
Version Affected: All Description: We have a default clock skew of 1 minute for calls to the Authentication API. This should be sufficient and we don't recommend increasing it. Instead, all th...
-
Internal: Connector Config Decrypt
Version Affected: All Description: When troubleshooting Connector issues, it's sometimes helpful to be able to decrypt the Connector Config so that you can see if the correct settings have been ...
-
Wrong ACS URL when setting SAML SSO
Version Affected: All Description: When configuring SAML SSO Identity Provider, the ACS URL in the UI is different to the ACS URL in the Metadata Cause: There is a bug with Vanity domains th...
-
How to avoid duplicate realms for IWA and MFA users
Version Affected: All Description: For On Prem/Hybrid customers who do not have both DMZ and Internal IdPs, there has always been an issue with allowing IWA/Windows SSO for the internal users bu...
-
OIDC Revoke Permissions screen
Version Affected: All Description: Users complain that they see the Revoke Permissions screen instead of the App after they login to an OIDC app. Cause: The OIDC Query String is missing from t...
-
Invalid User, Incorrect Group or Error Retrieving Contact information on New Experience Realms
Version Affected: 23.07 Description: In 23.07 using a New Experience application that has multiple Datastores listed a sporadic error occurs of either Invalid User, Incorrect Group or Error Retr...
-
SAML Error: Error Has Been Logged / Keyset does not exist
Version Affected: All Description: When accessing a SAML realm, the Users see an error "Error has been logged" this message is generic and can be caused by several different reasons. Looking in ...
-
Invicti SAML integration
Version Affected: All Description: This document is designed to help intergrate with Invicti Cause: Invicti requires the SAML assertion to be signed but not the SAML message. Resolution: ...
-
Password Reset error message not highlighted in red
Version Affected: 20.06 onwards Description: When a user attempts to change their password and it fails to change for a reason, such as not meeting complexity requirement, this is no longer high...