<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic automatic re-authentication after 60 minutes does not re-request user roles in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/automatic-re-authentication-after-60-minutes-does/m-p/1401383#M39077</link>
    <description>&lt;P&gt;&lt;FONT face="andale mono,times"&gt;We have installed AGS Server with SecMgr NEXT un-federated.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="andale mono,times"&gt;We do now have a complete prototype (AGS + SecMgr NEXT SOI + UserInfoService + LDAP emulator) up&amp;nbsp; running and working.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="andale mono,times"&gt;By chance (leaving AGS map services open in a Chrome browser (user logged on via HTTP Basic - no activity) for hours) we observed via our logs the following behavior:&lt;/FONT&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;Start a Chrome TAB with a secured map service. (no AGS-token)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;HTTP Basic authentication is triggered.&lt;/FONT&gt;&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;This involves two LDAP requests:&lt;/FONT&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is user a valid user?&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Get user’s entitlement roles.&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;Subsequently, the user gets to see the main map service page.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;The user then activated the “ArcGIS Online Map Viewer”&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;This triggers a second HTTP Basic authentication.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;Finally, the user is presented with the map view and he/she can now freely manipulate the map with no additional authentication requests.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;The user completes his map view tasks but leaves the map viewer open!&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;After ~60 minutes AGS server re-authenticates automatically via LDAP! &lt;STRONG&gt;However, AGS does not re-request the user’s roles!&lt;/STRONG&gt; (The user’s roles could have changed anytime within the previous 60 minutes))&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;After another ~60 minutes the very same pattern is repeated.&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;FONT face="andale mono,times"&gt;This behavior raises two issues:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;A user can basically stay logged on forever (or until AGS gets restarted).&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;Changes to the user’s entitlements will never be detected as long as he/she remains logged on.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Wed, 27 Mar 2024 12:37:19 GMT</pubDate>
    <dc:creator>TorNielsen</dc:creator>
    <dc:date>2024-03-27T12:37:19Z</dc:date>
    <item>
      <title>automatic re-authentication after 60 minutes does not re-request user roles</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/automatic-re-authentication-after-60-minutes-does/m-p/1401383#M39077</link>
      <description>&lt;P&gt;&lt;FONT face="andale mono,times"&gt;We have installed AGS Server with SecMgr NEXT un-federated.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="andale mono,times"&gt;We do now have a complete prototype (AGS + SecMgr NEXT SOI + UserInfoService + LDAP emulator) up&amp;nbsp; running and working.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="andale mono,times"&gt;By chance (leaving AGS map services open in a Chrome browser (user logged on via HTTP Basic - no activity) for hours) we observed via our logs the following behavior:&lt;/FONT&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;Start a Chrome TAB with a secured map service. (no AGS-token)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;HTTP Basic authentication is triggered.&lt;/FONT&gt;&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;This involves two LDAP requests:&lt;/FONT&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is user a valid user?&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Get user’s entitlement roles.&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;Subsequently, the user gets to see the main map service page.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;The user then activated the “ArcGIS Online Map Viewer”&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;This triggers a second HTTP Basic authentication.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;Finally, the user is presented with the map view and he/she can now freely manipulate the map with no additional authentication requests.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;The user completes his map view tasks but leaves the map viewer open!&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;After ~60 minutes AGS server re-authenticates automatically via LDAP! &lt;STRONG&gt;However, AGS does not re-request the user’s roles!&lt;/STRONG&gt; (The user’s roles could have changed anytime within the previous 60 minutes))&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;After another ~60 minutes the very same pattern is repeated.&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;FONT face="andale mono,times"&gt;This behavior raises two issues:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;A user can basically stay logged on forever (or until AGS gets restarted).&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="andale mono,times"&gt;Changes to the user’s entitlements will never be detected as long as he/she remains logged on.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 27 Mar 2024 12:37:19 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/automatic-re-authentication-after-60-minutes-does/m-p/1401383#M39077</guid>
      <dc:creator>TorNielsen</dc:creator>
      <dc:date>2024-03-27T12:37:19Z</dc:date>
    </item>
  </channel>
</rss>

