Skip to main content

TIMEOUT Issue

 Status Update:

Investigation into the recurring "Unauthorized" pop-up identified a probable cause in the Grafana configuration. The grafana.ini [auth] section contains:

login_maximum_lifetime_duration = 1m

In Grafana, a lowercase m means minutes, not months. This caps the maximum session lifetime at one minute, which matches the reported 30-second to 2-minute cycle of the "Unauthorized" pop-up and forced refresh. The Grafana default for this setting is 30d.

A secondary contributing factor is under review: whether Grafana is configured to use the Keycloak refresh token (use_refresh_token). Without it, Grafana cannot silently renew an expired access token, so the browser receives a 401 when Keycloak's access token lifespan elapses. Keycloak's default access token lifespan is 5 minutes, which could produce the same symptom at a different interval.

While troubleshooting this ticket, a separate and more severe defect was found: SSO users other than the first cannot be created in Grafana at all, due to duplicate email addresses inherited from the GTAC LDAP provider. That has been raised as its own bug and has a MOP prepared. The two issues are independent, but both touch the [auth.generic_oauth] configuration, so the fixes should be sequenced rather than applied in parallel.

No configuration changes have been made yet. All findings to date are from log review and config inspection.

Next Steps:

  1. Confirm whether login_maximum_lifetime_duration = 1m was set intentionally (for example as a security requirement) or is a units mistake. — Owner: [name]
  2. Capture Keycloak's Access Token Lifespan, SSO Session Idle, and SSO Session Max values from the realm's Sessions and Tokens settings, for comparison against the observed interval.
  3. Verify NTP sync between the Grafana and Keycloak hosts. Clock drift causes tokens to be treated as expired on arrival and produces intermittent 401s.
  4. Reproduce with browser developer tools open and capture the failing request, its 401 response, and the timestamp, to confirm which token is expiring.
  5. In test, correct login_maximum_lifetime_duration to 30d (or the approved value), restart Grafana, and monitor for a minimum of 30 minutes of idle and active use.
  6. If the pop-up persists, enable use_refresh_token = true and confirm Keycloak is issuing refresh tokens to the grafana client.
  7. Sequence against the user sync bug: apply that fix first in test, since it rewrites the same config section, then re-validate this issue.

Comments

Popular posts from this blog

Joke of Day

Home / Blog / 35 Cybersecurity Jokes to Make Any Security Geek Chuckle (or Groan) 35 Cybersecurity Jokes to Make Any SecurityGeek Chuckle (or Groan) Posted on September 8, 2020 Last updated on December 13, 2024. Good IT jokes are few and far between, especially when it comes to cybersecurity. That’s why we put on our creativityhats to brainstorm joke after joke – with a break to pull in a few of our favorites from the web – for the ultimate result: themotherlode (or should we say mother board ?) of cybersecurity jokes and puns. P.S.: we side with Alfred Hitchcock on thisone: puns are the highest form of literature. Everyone deserves an eye-catching intro to break the ice at the start of a meeting or spice up a PowerPoint – gotta keepthe CEO’s attention somehow! And no joke is complete without the perfect graphic. Feel free to grab ours and includethem in your next newsletter, quarterly presentation, or for a workday pick-me-up. Without further ado, we present… Our Favorite Cybersecurit...

3/19

 Greetings. The last few days on this weight management program as been a bit crazy.  I had serious cravings.  Then I did some serious yard work then took a shower.  After that I felt like I would faint.  Chiquita and I had to go and get some powerade.  I ate some crackers as well and it seem to help.  Tomorrow back to the weight management grind.  :) G 283.1 lb

Single Step

  Starting a new weight loss journey today.  I will be working with Houston Methodist Hospital Medical Weight Management Center.  Met with the staff today and it seems to be a very positive environment. I am a bit worried about starting this process but glad I'm starting.   Details:  In this program, I will be placed on a Very Low Calorie Diet (VLCD), which involves consuming 800 calories in the form of meal replacements and no more than 50 grams of carbohydrates per day. My body should respond by going into ketosis, a metabolic state in which the body uses fat stores as its primary energy (ketone bodies).  And I have a lot of fat stored.   Start Date 3/14.   G