[SOLVED] Timeout after Login with OpenID Connect and AzureAD

Jun 30, 2020
23
1
8
Hello,

we set up OpenID Connect on our PVE 7.4 Cluster, authenticating against AzureAD.

When selecting the OIDC-realm for login, PVE does correctly redirect to the Microsoft-Login. However, after logging in on AzureAD and being redirected back to PVE, PVE just shows a busy pointer and after a while a timeout error appears:


Bildschirmfoto 2024-01-10 um 13.48.06.png

We have been suspecting an issue with the local user name not matching whatever is returned via OIDC. So we tried all possible username claims and changing the scopes, but at best still had the timeout - at worst received an error about scopes not being available at all.

We also tried not creating the user manually and instead set the Autocreate Users option, to see how PVE would spell out the user names. This still ended in a timeout - and no user was created in PVE at all.

The AzureAD ist not under our own administration, so our diagnosing on that end is very limited. Their support has not been able to find anything resolving the problem.

Can you help us with diagnosing and fixing this timeout issue? At the moment, we are out of ideas where to even look.

regards,
Andreas

P.S.: We also checked that the (manually created) local user supposed to match had Audit permissions, so the login doesn't just fail due to not being able to access PVE. Didn't help either, though.
 
Last edited:
Eventually, we found the culprit.

The IPS subsystem of a firewall was blocking parts of the network communication - without logging the events, of course, so we didn’t find it right away.

I'm marking this thread Solved.

regards,
Andreas
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!