Gary Chang
Articles
-
SameSite Patch for Unsupported IdP Versions
Note: Google has delayed the rollout of the SameSite attribute enforcement in Chrome 80 until Feb. 17. This notice applies to SecureAuth IdP versions: 7.4.3 8.0.1 8.0.2 8.0.3 8.1 8.2 9.0 9.01 9...
-
Preventing slow realm response times during periods of inactivity
SecureAuth IdP Version Affected: All Description: Occasionally, realm authentication may take more than 20 seconds and ultimately time out. Cause: This could be the worker process being terminate...
-
Group Filter Expression is Unable to Locate Specific Groups
Description: You may not be able to see the groups being passed in an attribute as a result of the filter being used, as some vendors may recommend using _* as the filter when a vast amount of grou...
-
Ensuring Groups are Being Passed as an Attribute in SAML Assertion
Description: During a new integration, you may want to verify that certain groups are being passed as part of an attribute. Resolution: In order to confirm, you can run a SAML trace in Firefox by u...
-
FileSync fails to restore backup from primary server
SecureAuth IdP Version Affected: All Description: When restoring a backup on a secondary server using FileSync, the installer may fail at certain points. Sometimes an error message is generated tha...
-
Bypass group in Login for Windows fails when using Group scope of Domain local
Login for Windows version affected: 1.0.3 Windows OS versions affected: 7 Description: When a user is part of a bypass group with the Group scope of Domain local, he or she will receive the foll...
-
Configuring Redirect within IdP by User Agent
SecureAuth IdP Version Affected: All Description: As an alternative to configuring redirects in IIS, you can also modify the Mobile Identifiers in an IdP realm for a specific user agent to redire...
-
Vulnerability was identified on the SecureAuth server: 'Weakness Name: Microsoft EMET < 5.5 Security Bypass Vulnerability'
SecureAuth IdP Version affected: 9.1 Description: When running a security scan for vulnerabilities, your software flags the following on the SecureAuth server: Weakness Name: Microsoft EMET < 5.5...
-
Prevent SecureAuth Realms from Being Indexed by Search Sites
Description: External SecureAuth realms can be discovered through search engines. Cause: These external sites are publicly accessible. Resolution: In order to prevent search engines from crawling y...