<div dir="ltr"><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">We are mostly seeing this with the Global Protect client (>99.9%), but we are also seeing this with logins to our Microsoft Online, having nothing to do with the Global Protect client.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">Our Azure tenant is federated back to our Shibboleth IdP. Logging in to Microsoft 365 desktop apps pops up an embedded browser with the first MS online login screen, asking you for your "email address". That window redirects to our IdP, and from there it's just like what we've been experiencing with Global Protect client logins. (I believe our Global Protect workaround is that we have reverted the GP client to the previous version and turned off automatic checking for updates.)</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">We don't typically deploy MS 365 versions of those apps, so this affects maybe a half dozen of our users, and they've all learned to click the sign-in button instead of pressing enter.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">Anyway, there is definitely something in our login pages that triggers the issue with the MS embedded browser technology, and definitely something in the Global Protect client update that exacerbates it.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">Here's a question: is anyone seeing this problem after having switched to the Duo Universal Prompt? Some folks here are hoping that going to the Universal Prompt might alter things enough that the GP client problem will go away. We had to tweak our javascript when we first deployed SSO in the GP client several months ago because our javascript used a method that wasn't implemented in the embedded browser. (That was a lot of fun debugging, by the way.)</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">-Les</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div><div dir="ltr" data-smartmail="gmail_signature"><div dir="ltr"><div><br></div><div><table style="color:rgb(136,136,136);border:none;border-collapse:collapse"><tbody><tr style="height:0pt;border-top:1pt solid rgb(204,204,204)"><td style="border-right:1pt solid rgb(204,204,204);vertical-align:middle;padding:5pt;overflow:hidden"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:0pt"><a href="http://www.carleton.edu/" target="_blank"><span style="font-size:11pt;font-family:Arial;color:rgb(17,85,204);vertical-align:baseline;white-space:pre-wrap"><span style="border:none;display:inline-block;overflow:hidden;width:70px;height:73px"><img height="73" src="https://lh6.googleusercontent.com/QEL1To3Ci_dJA1huaKzfZ0Lf4MaZlAy_f-W3vQjbyzNq_yXq_ZYGv3tuT4dkaZS_bZ5X6fZR4iKzBboZhxbCF5htZFnLNKGqmrzHsVJtsjsy0pfK5w2z0Dlq-EtZcWhv0PxBpWmR" width="70" style="margin-left:0px;margin-top:0px"></span></span></a></p></td><td style="border-left:1pt solid rgb(204,204,204);vertical-align:top;padding:10.8pt;overflow:hidden"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><font color="#dea410" face="Arial"><span style="font-size:14.6667px;white-space:pre-wrap"><b>Les LaCroix '79</b></span></font></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">Strategic Technologist</span></span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">Information Technology Services</span></span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">t: (507) 222-5455</span></span></p></td></tr></tbody></table></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, May 13, 2022 at 7:37 AM Nickles, Brent via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">This issue is gaining traction on our campus....has anyone come up with a workable solution and/or any word if Palo is going to supply a patch?<br>
<br>
-----Original Message-----<br>
From: users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> On Behalf Of Cantor, Scott via users<br>
Sent: Friday, April 29, 2022 4:36 PM<br>
To: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Cc: Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
Subject: Re: Palo Alto Global Protect embedded browser + Shibboleth<br>
<br>
CAUTION: This message originated from a non-UMB email system. Hover over any links before clicking and use caution opening attachments.<br>
<br>
> Not being a programmer, I'm hoping this makes sense to someone with specific knowledge of the logon page<br>
<br>
I don't know what Windows is doing underneath, what matters is the HTTP requests it issues. You would need to trace the traffic and identify what it's actually communicating, but my guess is they have a bug and it's not passing the cookie(s) back in. The exception in the log will be explicit about why it broke. "Conversation not found" basically means the cookies didn't get sent, and it will also issue a new JSESSIONID in response also. There's no "API explanation" for that, that's a broken user agent.<br>
<br>
I would, I suppose, suggest that your workaround would be some kind of Javascript in the login template to try and interfere with it and prevent whatever it might be doing with the enter key, but that's beyond my experience level.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cbnick001%40umaryland.edu%7Cb42a24cee9ac49ada1e208da2a1fda1f%7C3dcdbc4a7e4c407b80f77fb6757182f2%7C0%7C0%7C637868613543562169%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=eOADBkbigAIy%2BnRllitkuw%2Fj%2FTwSr32xR0BI6JeRgzo%3D&reserved=0" rel="noreferrer" target="_blank">https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cbnick001%40umaryland.edu%7Cb42a24cee9ac49ada1e208da2a1fda1f%7C3dcdbc4a7e4c407b80f77fb6757182f2%7C0%7C0%7C637868613543562169%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=eOADBkbigAIy%2BnRllitkuw%2Fj%2FTwSr32xR0BI6JeRgzo%3D&reserved=0</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>