[CATO] Fwd: LAST UPDATE - ctcLink Login Issues and Fixes

Monica Olsson molsson at sbctc.edu
Fri Aug 27 08:20:17 PDT 2021



Get Outlook for iOS<https://aka.ms/o0ukef>
________________________________
From: Dani Bundy <dbundy at sbctc.edu>
Sent: Thursday, August 26, 2021 12:44:26 PM
To: SBCTC All Staff <SBCTCAllStaff at sbctc.edu>; ctclink_poc at lists.ctc.edu <ctclink_poc at lists.ctc.edu>
Subject: LAST UPDATE - ctcLink Login Issues and Fixes


Good afternoon,



I am happy to provide the last update in regards to the ctcLink login issues and fixes, as the last issue has been resolved.



Open Issues

None



Resolved Issues



User getting caught in mobile view

Issue:                  User cookies from the HCX Mobile app are being picked up in the Okta gateway portal. Staff can't get back to the gateway portal once this happens.

Cause:                 An HCX HighPoint mobile cookie has been identified as the root cause.

Status:                We are testing a fix that removes the urltest cookie when a user logs out.

PAST UPDATE: A temporary solution has been put into place with a new HCX HighPoint mobile logout page (see image below). This has been created to remove the HCX cookie and allows the user to proceed back to the HCX mobile springboard or close their browser tab. If the user closes the browser tab, they will log in to the gateway portal without being redirected back to the mobile view.



 [Graphical user interface, text, application, email  Description automatically generated]

Figure 1 High Point mobile logout page. Showing "You have been logged out of your ctcLink account. You can close your browser. Or go back to mobile site."

New UPDATED:  User can now open Mobile site (m.ctclink.us) and regular ctcLink webpage (gateway.ctclink.us) in the same browser session.



Thank you,



[Compass]Dani Bundy

Director of ctcLink PeopleSoft Customer Support



From: Dani Bundy
Sent: Monday, August 23, 2021 9:23 AM
To: ctclink_poc at lists.ctc.edu; SBCTC All Staff <SBCTCAllStaff at sbctc.edu>
Subject: NEW UPDATES - ctcLink Login Issues and Fixes



Good Morning,



Below are some updates to the login issues and new fixes that have been put into place. Please reach out if there are any questions about this information.



Resolved Issues



The spinning wheel at the login page

Issue:                  Users get hung up in the login process.

Cause:                This was due to an OKTA/OAG change made in version 6 that changed the way some site cookies are handled.

Fixed:                  A fix has been put into place that now stops the spinning wheel at login due to the older supported ctcLink browser version. Also, if a user is using an older unsupported browser, they will receive a browser warning message telling them, "You are on an unsupported browser version. Please update your browser to avoid any login and general ctcLink issues." We have found during this Okta deployment that other ctcLink issues may also be resolved by using a browser supported by PeopleSoft. Below is a list of the current browser versions supported by PeopleSoft and a sample of the browser message.



Please pass this information on to your local help desk and ask them to check the users' browser version during any ctcLink troubleshooting.



ctcLink Reference Center for Okta - http://ctclinkreferencecenter.ctclink.us/m/79750/c/363391





[Graphical user interface, application  Description automatically generated]

Figure 1- Image states " You are on an unsupported browser version. Please update your browser to avoid any login and general ctcLink issues.



Minimum browser version

Browsers



Apple Safari

1 Release (12)

Google Chrome

1 Release (69)

Microsoft Edge

2 Releases (79.0.309.71, 42+)

Microsoft Internet Explorer

1 Release (11)

Mozilla Firefox

2 Releases (62, 60 ESR)



Students seeing a strange page, unable to get to the login page

Issue:                  Non-English language login page error. Some users are missing the ctcLink/Okta login page in the login frame.

Cause:                 This is due to a bug in the Okta login widget when java i18n was used to customize the text areas in the Okta login widget.

Fixed:                  A fix has gone into place that allows the java i18n not to interfere with anything language login process.





Open Issue



User getting caught in mobile view

Issue:                  User cookies from the HCX Mobile app are being picked up in the Okta gateway portal. Staff can't get back to the gateway portal once this happens.

Cause:                 An HCX HighPoint mobile cookie has been identified as the root cause.

Status:                We are testing a fix that removes the urltest cookie when a user logs out.

PAST UPDATE: A temporary solution has been put into place with a new HCX HighPoint mobile logout page (see image below). This has been created to remove the HCX cookie and allows the user to proceed back to the HCX mobile springboard or close their browser tab. If the user closes the browser tab, they will log in to the gateway portal without being redirected back to the mobile view.



 [Graphical user interface, text, application, email  Description automatically generated]

Figure 1 High Point mobile logout page. Showing "You have been logged out of your ctcLink account. You can close your browser. Or go back to mobile site."

New UPDATED: We have a fix we are working on implementing in production.  The fix will be the same process flow as above, with one exception, when a user lands on the mobile page, the HCX cookie will not be applied until the user logins.





Thank you,

[Compass]Dani Bundy

Director of ctcLink PeopleSoft Customer Support



From: Dani Bundy
Sent: Friday, August 13, 2021 9:57 PM
To: ctclink_poc at lists.ctc.edu<mailto:ctclink_poc at lists.ctc.edu>; SBCTC All Staff <SBCTCAllStaff at sbctc.edu<mailto:SBCTCAllStaff at sbctc.edu>>
Subject: NEW UPDATE - ctcLink Login Issues and Fixes



Good Evening,



Providing some additional updates about the ctclink login issues and fixes below.

Spinning wheel at the login page

Issue:                   Users get hung up in the login process.

Cause:                 Random callback loops (automatic actions based on code), possibly related to session cookie naming conflicts between load balancers (the method of distributing incoming application traffic).

Previous Status: Actively investigating and working with Okta Support to determine the issue.

•       Logs are indicating " RESULT="DENY" REASON="INVALID_AUTHCOOKIE"

•       It appears users are moving between worker cluster nodes during a session, resulting in a session cookie being invalid. This results in a user going into a loop or being logged out of a session.

UPDATED Fix:   It has been discovered that the spinning wheel at login has been caused by an unsupported browser version for both Okta and ctcLink.  Below are the minimum browser versions that are supported by ctcLink.

Minimum browser version

Desktop Applications, Browsers and Clients



Apple Safari

1 Release (12)

Google Chrome

1 Release (69)

IBM DB2 Client

2 Releases (11.1, 10.5)

IBM DB2 Connect

2 Releases (11.1, 10.5)

Microsoft Edge

2 Releases (79.0.309.71, 42+)

Microsoft Excel

5 Releases (2019,2016,2013,2010,365)

Microsoft Internet Explorer

1 Release (11)

Microsoft SQL Server Client

4 Releases (2019,2017,2016,2014)

Microsoft Word

2 Releases (2016,2013)

Mozilla Firefox

2 Releases (62, 60 ESR)

Oracle Database Client

4 Releases (19.0.0.0.0, 18.0.0.0.0, 12.2.0.1.0, 12.1.0.2.0)

Students seeing a strange page, unable to get to the login page
Issue:                  Non-English language login page error. Some users are missing the ctcLink/Okta login page in the login frame.
Cause:                 Under investigation
Previous Status: We have initiated a case file with Okta Support to identify the root cause.

UPDATED Status: We have been able to reproduce the missing login page for certain languages in the browser. Updated logs have been sent to Okta support and we are   currently working with them to resolve the issue. Temporary work arounds are to use English as the browser language or use a non-incognito browser.



Fix ETA:             Wednesday, Aug. 18, 2021



Please let me know if there are any questions or additional issues.



Thank you,

[Compass]Dani Bundy

Director of ctcLink PeopleSoft Customer Support



From: Dani Bundy
Sent: Friday, August 6, 2021 9:59 PM
To: ctclink_poc at lists.ctc.edu<mailto:ctclink_poc at lists.ctc.edu>; SBCTC All Staff <SBCTCAllStaff at sbctc.edu<mailto:SBCTCAllStaff at sbctc.edu>>
Subject: UPDATE - ctcLink Login Issues and Fixes



Good evening,



Providing some additional updates that have been addressed to the open ctcLink login issues.

Spinning wheel at the login page

Issue:                  Users get hung up in the login process.

Cause:                 Random callback loops (automatic actions based on code), possibly related to session cookie naming conflicts between load balancers (the method of distributing incoming application traffic).

Status:                Actively investigating and working with Okta Support to determine the issue.

•       Logs are indicating " RESULT="DENY" REASON="INVALID_AUTHCOOKIE"

•       It appears users are moving between worker cluster nodes during a session, resulting in a session cookie being invalid. This results in a user going into a loop or being logged out of a session.

UPDATED Fix:  A temporary solution has been put into place to stop the spinning wheel at login. We are still investigating the root cause for a permanent fix.

  *   If users are still experiencing the spinning wheel at the login, please let us know by providing a timestamp and the user ID that is having this issue.

User getting caught in mobile view

Issue:                  User cookies from the HCX Mobile app are being picked up in the Okta gateway portal. Staff can't get back to the gateway portal once this happens.

Cause:                 An HCX HighPoint mobile cookie has been identified as the root cause.

Status:                We are testing a fix which removes the urltest cookie when a user logs out.

UPDATED Fix: : A temporary solution has been put into place with a new HCX HighPoint mobile logout page (see image below). This has been created to remove the HCX cookie and allows the user to proceed back to the HCX mobile springboard or close their browser tab. If the user closes the browser tab, they will be able to login to the gateway portal without being redirected back to the mobile view.

 [cid:image011.png at 01D79A78.1869D120]

Figure 1 High Point mobile logout page. Showing "You have been logged out of your ctcLink account. You can close your browser. Or go back to mobile site."

Please reach out if you have additional questions.

Thank you,

[Compass]Dani Bundy

Director of ctcLink PeopleSoft Customer Support



From: Dani Bundy
Sent: Friday, August 6, 2021 8:35 AM
To: ctclink_poc at lists.ctc.edu<mailto:ctclink_poc at lists.ctc.edu>
Subject: ctcLink Login Issues and Fixes Update



Dear ctcLink College & SBCTC Points of Contact and SBCTC staff:



The ctcLink Login process was upgraded on Saturday, July 31, 2021 with new Okta identity verification and security preferences. SBCTC’s IT Support team is actively working to respond to several reported issues. See below for current open issues and resolved/fixed issues.



Thank you for your feedback and patience as we resolve these items.



Please share this message as appropriate.

Open Issues

Spinning wheel at the login page

Issue:                  Users get hung up in the login process.

Cause:                 Random callback loops (automatic actions based on code), possibly related to session cookie naming conflicts between load balancers (the method of distributing incoming application traffic).

Status:                Actively investigating and working with Okta Support to determine the issue.

•       Logs are indicating " RESULT="DENY" REASON="INVALID_AUTHCOOKIE"

•       It appears users are moving between worker cluster nodes during a session, resulting in a session cookie being invalid. This results in a user going into a loop or being logged out of a session.

Fix Estimated:   Tuesday, Aug. 10, 2021

User getting caught in mobile view

Issue:                  User cookies from the HCX Mobile app are being picked up in the Okta gateway portal. Staff can't get back to the gateway portal once this happens.

Cause:                 An HCX HighPoint mobile cookie has been identified as the root cause.

Status:                We are testing a fix which removes the urltest cookie when a user logs out.

Fix ETA:               Tuesday, Aug. 10, 2021

Students seeing a strange page, unable to get to the login page

Issue:                  Non-English language login page error. Some users are missing the ctcLink/Okta login page in the login frame.

Cause:                 Under investigation

Current status: We have initiated a case file with Okta Support to identify the root cause.

Fix ETA:               To be determined

Resolved/Fixed Issues

Pillar logout issues

Issue:                  When the "Logout" link was used, it was taking about two minutes to complete.

Cause:                 PeopleSoft internal single sign-on (SSO) feature was not communicating with each server and but instead with the user's browser session.

Fix:                       A new internal communication path allows a server to not use Okta Gateway as a proxy for portal communications while performing a server-to-server call (two or more servers communicating directly with each other).

Active Directory (AD) password changes not populating local PeopleSoft pillars for W2 and W4 functions

Issue:                   Password changes in Okta needed to not only be synced with ctcLink AD, but also into each pillar (except portal).

Cause:                 Testing found that some functions in PeopleSoft require PeopleSoft Authentication.

Fix:                       We created a SCIM/API/Lambda function to push password changes into the needed PeopleSoft pillars.

PeopleSoft (PS) Mobile Token Conflict

Issue:                  Mobile Guest PS Token is not being removed or overwritten during the login process.  (PS Token is a cookie embedded into the browser memory of a user authenticated by the PS web server. As long as the cookie is active, a user can browse that PS application without entering login details again.)

Cause:                 When a user first goes to the HCX Mobile portal, they log in as a Guest. This creates a Guest PS Token which was then getting cached (stored) in the user's browser session, interfering with future logins.

Fix:                       Okta Access Gateway now deletes the guest PS Token during the login process.

If you have questions, please reach out and I will connect you with the technical team.



Thank you,

[Title: SBCTC logo - Description: Compass]

Dani Bundy

ctcLink PeopleSoft Customer Support Director

Washington State Board for Community and Technical Colleges

dbundy at sbctc.edu<mailto:dbundy at sbctc.edu> • c: 360-619-8960 o: 360-704-1028 • sbctc.edu






-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.png
Type: image/png
Size: 18063 bytes
Desc: image001.png
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0006.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.jpg
Type: image/jpeg
Size: 629079 bytes
Desc: image002.jpg
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0004.jpg>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image004.png
Type: image/png
Size: 64902 bytes
Desc: image004.png
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0007.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image005.jpg
Type: image/jpeg
Size: 2629 bytes
Desc: image005.jpg
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0005.jpg>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image006.png
Type: image/png
Size: 76268 bytes
Desc: image006.png
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0008.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image009.png
Type: image/png
Size: 64902 bytes
Desc: image009.png
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0009.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image010.jpg
Type: image/jpeg
Size: 2631 bytes
Desc: image010.jpg
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0006.jpg>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image011.png
Type: image/png
Size: 64937 bytes
Desc: image011.png
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0010.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image012.jpg
Type: image/jpeg
Size: 2629 bytes
Desc: image012.jpg
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0007.jpg>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image013.png
Type: image/png
Size: 15649 bytes
Desc: image013.png
URL: <http://lists.ctc.edu/pipermail/cato_lists.ctc.edu/attachments/20210827/e3dba91c/attachment-0011.png>


More information about the CATO mailing list