Issue metadata
Sign in to add a comment
|
Duo Security in chrome-signin page
Reported by
elli...@iu.edu,
Mar 28 2017
|
||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.110 Safari/537.36 Steps to reproduce the problem: 1. Attempt to sign in to Chrome with an account protected by 2FA (Duo Security) 2. Input SSO credentials 3. When redirected to the Duo Security page, all that displays is a flashing, empty box What is the expected behavior? Successful login to Chrome. What went wrong? This works fine when authenticating HTTP pages in the browser - I can access everything. The issue only occurs when attempting to sign in to Chrome using the chrome://chrome-signin page. Did this work before? N/A Chrome version: 57.0.2987.110 Channel: stable OS Version: OS X 10.12.4 Flash Version: This was working previously and I've been using it for months. I just reformatted a Mac and reinstalled OS 10.12.4. The first thing I did was install Chrome (57.0.2987.110 (64-bit)) and attempt to sign in. This was referenced in #501149 and was closed as fixed, but appears to have reared its head again.
,
Mar 29 2017
Jérôme, can you try to reproduce it, please?
,
Mar 29 2017
Hello Elliott It looks like the SAML flow is broken for 2FA. What is your 2FA? Do you know if there is a way for us to get an account on this domain so we can reproduce it? Do you know how to get logs from the Chrome console? Is there anything relevant? Thanks,
,
Mar 29 2017
Hello Elias, Do you have idea how to debug that issue? Thanks,
,
Mar 29 2017
I am familiar with saving logs, but I am not sure what I am looking for or what you would need. I'm happy to help diagnose if you can steer me toward the type of information that would be most helpful. We use Duo Security as our two-factor authentication provider. https://duo.com/ Please bear in mind that I am a tech-savvy end user, not a hard-core developer. I will help as much as I can.
,
Mar 29 2017
Thanks for the report, Elliott. +Mihai - do we have any POCs on the SAML side of things that we could loop in?
,
Mar 30 2017
,
Mar 30 2017
I think we need to follow-up the SAML issue internally with Gaia engineers. I'll send them an email about this.
,
Mar 30 2017
Internal bug b://36771209
,
Mar 30 2017
We believe this is a problem with the it.edu Identity Provider- the ID provider does not finish the sign-in flow. I think you should open this bug with them (not with Chromium).
,
Mar 30 2017
,
Mar 30 2017
I'm sorry, but I'm not sure what that means. If you're saying it's a problem with IU.edu, I do not know how that could be. I have been able to do this in the past in a previous version of Chrome. In fact, I am on a different computer and am signed in right now. There is also no problem with the 2FA in a standard HTTP page - it's only the chrome://chrome-signin page that this fails. If there is any logging or other detail that I can provide, please let me know what you need.
,
Mar 31 2017
We have tested with an internal test Saml domain we use and it worked fine for the chrome://chrome-signin works. chrome://chrome-signin uses a special context (WebUI) for additional security (for example, the cookie store is separate from the main cookie store). I do not know how 2FA works on this site (or how Duo Security works), so I do not know what the requirements for this IdP are. It is not clear to me how we can debug (or test this). I think the IdP is in a better position to debug this flow.
,
Apr 14 2017
--Chrome Identity automated triaging-- This bug is Unconfirmed and has gone two weeks without any activity, so it is being closed as WontFix. Please re-open if this is still a valid and reproducible bug or feature request and mark it as Available. Please see https://goo.gl/78kbny for more details. Please remove the Services>SignIn or UI>Browser>Profiles components if this bug isn't related to Chrome Identity. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by patricia...@chromium.org
, Mar 28 2017