Latest Google Chrome breaks AWS Client VPN SAML Auth

7

I'm on Google Chrome 123.0.6312.58-1 (Ubuntu 22.04.4 amd64) that got updated to this version today. Since this version I'm not able to authenticate to AWS Client VPN with Okta SAML: Enter image description here What I see in AWS Client VPN logs is this: 2024-03-20 19:35:15.978 +02:00 [DBG] >LOG:1710956115,,AUTH: Received control message: AUTH_FAILED,CRV1:R:instance-1/73[…]

Fellow team mates confirmed they have the same experience on latest Chrome on Linux and on Windows. Alt browsers like Firefox and MS Edge work just find and don't fail AWS Client VPN authentication.

Any hints on how to resolve?

UPD: AWS Client VPN version is 3.12.1

UPD2: Chrome on WindowsEnter image description here

UPD3: same has been reported by someone else on Reddit — https://www.reddit.com/r/aws/comments/1bjh4he/windows_aws_vpn_client_not_working_with_latest/

  • This is also happening at my org for users on both Mac and Linux, each using clients 3.9.1 and 3.12.1, respectively. Azure SAML in our case.

  • Best not to upgrade your browsers it seems. Safari broke for me first. Chrome worked but then I went to check the version and that point it helpfully upgraded, breaking that work around. Just wanted to chime in and add Latest macOS/Safari/VPN Client/Chrome and very broken. Using Google as our SAML/Idp with the Application ACS URL configured as "http://127.0.0.1:35001". Others have tried to change that to https with no luck.

    My re:Post: https://repost.aws/questions/QUrtBrUIkeQjCWINLH-g3RDA/aws-vpn-client-login-fails-with-safari

yz
preguntada hace 2 meses2095 visualizaciones
1 Respuesta
0

I've received confirmation that the aws client vpn team is aware of the issue and are addressing it, ref. I've also found that this chrome update is affecting other sso clients I use. It is still possible to use chrome and work around this, while the clients address their underlying issues, disable the chrome flag (chrome://flags/) "Reduce waiting time for Private Network Access preflights response"

respondido hace 2 meses
profile picture
EXPERTO
revisado hace un mes

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas