| Summary: | Network Manager's openconnect anyconnect plugin stoped to work with oath2 in Palo Alto Firewall | ||
|---|---|---|---|
| Product: | [Applications] systemsettings | Reporter: | Alan Aguinaga <alansenairj> |
| Component: | kcm_networkmanagement | Assignee: | Plasma Bugs List <plasma-bugs-null> |
| Status: | REPORTED --- | ||
| Severity: | grave | CC: | jgrulich, kdedev, nate |
| Priority: | NOR | ||
| Version First Reported In: | 6.4.4 | ||
| Target Milestone: | --- | ||
| Platform: | Fedora RPMs | ||
| OS: | Linux | ||
| See Also: | https://bugs.kde.org/show_bug.cgi?id=494867 | ||
| Latest Commit: | Version Fixed/Implemented In: | ||
| Sentry Crash Report: | |||
| Attachments: | problem | ||
|
Description
Alan Aguinaga
2025-09-05 16:44:10 UTC
Created attachment 184753 [details]
problem
error screen
What is PaloAlto OS? Can you describe the operating environment? Is it a home machine or a work machine? Is there in fact a system adminstrator you can contact for assistance? 🐛🧹 ⚠️ This bug has been in NEEDSINFO status with no change for at least 15 days. Please provide the requested information, then set the bug status to REPORTED. If there is no change for at least 30 days, it will be automatically closed as RESOLVED WORKSFORME. For more information about our bug triaging procedures, please read https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging. Thank you for helping us make KDE software even better for everyone! (In reply to Nate Graham from comment #2) > What is PaloAlto OS? Can you describe the operating environment? Is it a > home machine or a work machine? Is there in fact a system adminstrator you > can contact for assistance? this is not a problem at conection or user itself because paloalto app and gpclient works. only network manager not works and the paloalto is using latest version. after firewall update SAML stop to pass something to internal networkmanager browser to accept connections. last log: POST https://a.b.c/global-protect/prelogin.esp?tmp=tmp&clientVer=4100&clientos=Linux Attempting to connect to server 1.2.3.4:443 Connected to 1.2.3.4:443 SSL negotiation with myserver.com Connected to HTTPS on myserver.com with ciphersuite (TLS1.2)-(ECDHE-SECP256R1)-(RSA-SHA256)-(AES-256-GCM) Got HTTP response: HTTP/1.1 200 OK Date: Sat, 11 Oct 2025 18:57:52 GMT Content-Type: application/xml; charset=UTF-8 Content-Length: 1592 Connection: keep-alive Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Set-Cookie: SESSID=4f22744a-251e-492b-96f4-4076a8b106cf; Path=/; SameSite=Lax; HttpOnly; Secure X-Frame-Options: DENY Strict-Transport-Security: max-age=31536000; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; img-src * data:; style-src 'self' 'unsafe-inline'; frame-ancestors 'none'; HTTP body length: (1592) SAML REDIRECT authentication is required via https://login.microsoftonline.com/3737ddf7-0b60-4f73-a0ce-2abe5bb94cf4/saml2?SAMLRequest=lZLNboMwEIRfBfkOmH9qBSSaHBopVVGgPfRS2cYklsBOvabq4xeSVk0vkXpc7eib3dldAR2HE6kme1R78T4JsM7nOCgg50aBJqOIpiCBKDoKIJaTpnrckdDD5GS01VwPyKkAhLFSq7VWMI3CNMJ8SC6e97sCHa09AfF9OlmhrOTUm5QcRceOHtejxwyJ48hfqCH2m9qv1g1yNvMkUtGF%2BUsY9EEqb5TcaNC91WqQSiwQP8qirOv6zMUsxW7cZ5FLMRduSJlIGLuLeR%2F7y0ohcrabAr3hKM%2BCWcKyKE0wxj1L4ySPc5z2SdCLaJYBTGKrwFJlCxTiMHED7AZBG%2BQkyUgSviKn%2Fk7gXqpOqsPtuNhFBOShbWu3fmpa5LwIA%2BcVZwEqV8uE5Gxsrs5wG0t%2FskflP5Ne%2BVd%2B5aX6%2BwvlFw%3D%3D&RelayState=dFYEAGBgtmg0ZjIyNzQ0YS0yNTFlLTQ5MmItOTZmNC00MDc2YThiMTA2Y2Yw POST https://myserver.com/global-protect/getconfig.esp Got HTTP response: HTTP/1.1 512 status code 512 Date: Sat, 11 Oct 2025 18:57:53 GMT Content-Type: application/xml; charset=UTF-8 Content-Length: 0 Connection: keep-alive Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Set-Cookie: SESSID=a0dcf005-b2ff-4acc-a6bb-abce6832a457; Path=/; SameSite=Lax; HttpOnly; Secure X-Frame-Options: DENY X-Private-Pan-Globalprotect: auth-failed HTTP body length: (0) Unexpected empty response body from server Networkmanager plugin to open a browser dialog is not working. I got administrator help and my user can log using https://github.com/yuezk/GlobalProtect-openconnect NetworkManager used to work and pass auth to mini browser but now it stopped to work. And my other notebook with clean install is not working too. What log or info do you need to get? "PAN-OS" is the software in question https://docs.paloaltonetworks.com/pan-os > PAN‑OS® is the software that runs all Palo Alto Networks® next-generation firewalls. Unfortunately I don't have an account with PaloAlto to test with, I'll leave this for someone who does. |