Skip to content

Conversation

@bergerhoffer
Copy link
Contributor

@bergerhoffer bergerhoffer commented Sep 16, 2025

@bergerhoffer bergerhoffer added this to the Planned for 4.20 GA milestone Sep 16, 2025
@openshift-ci openshift-ci bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Sep 16, 2025
@ocpdocs-previewbot
Copy link

ocpdocs-previewbot commented Sep 16, 2025

🤖 Tue Sep 30 16:17:42 - Prow CI generated the docs preview:

https://99127--ocpdocs-pr.netlify.app/openshift-enterprise/latest/release_notes/ocp-4-20-release-notes.html

@bergerhoffer
Copy link
Contributor Author




* When using GitLab as the external OIDC identity provider for direct authentication, clicking *Log out* from the {product-title} web console does not log you out of the console. (link:https://issues.redhat.com/browse/OCPBUGS-61649[OCPBUGS-61649])
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@bergerhoffer , Google has same logout issue.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, need add google has the same issue.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@bergerhoffer for ADFS as the provider, there is a bug https://issues.redhat.com/browse/OCPBUGS-62142.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@xingxingxia https://issues.redhat.com/browse/OCPBUGS-62142 I think the bug is critical, if we need to wait the bug to be fixed to add the ADFS in 4.20 docs?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@wewang58 , I identified the root cause of https://issues.redhat.com/browse/OCPBUGS-62142 in its comment and updated the bug title with the root cause. It is ADFS refresh token too long. Then the console developer is looking into it. Anyway, I retried using the ADFS you installed and attempted 4 console logins:
1 I found 3 attempts failed but 1 succeeded. For each of the 3 failing logins, the "too long" message was printed. For the 1 success, the value wasn't considered too long, therefore the "too long" message wasn't printed. So users can have some chance of login success.
2 Even if in the failed console logins, clicking "Try again" can make the console login finally succeed as a workaround which you ever encountered too.
3 oc login works well
Based on this, maybe we can add ADFS in doc but with a known bug mentioned with the workaround noted.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@xingxingxia Yes, agree with you.

@bergerhoffer bergerhoffer force-pushed the OSDOCS-14939-known-issues branch from 390d8e3 to 0c3dfbc Compare September 30, 2025 15:24
@bergerhoffer bergerhoffer force-pushed the OSDOCS-14939-known-issues branch from 0c3dfbc to 22cd41c Compare September 30, 2025 15:57
@openshift-ci
Copy link

openshift-ci bot commented Sep 30, 2025

@bergerhoffer: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@bergerhoffer
Copy link
Contributor Author

@wewang58 @xingxingxia I added the known issue for ADFS, can you please take a look? I wasn't really clear on the exact workaround from the steps noted, so I put generically about reloading. But let me know if there's something more specific we should say here.

@wewang58
Copy link

@bergerhoffer I think it's enough, we already has the bug attached.
LGTM

@xingxingxia
Copy link
Contributor

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Oct 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

branch/enterprise-4.20 lgtm Indicates that a PR is ready to be merged. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants