Incident Report Number: 2015-016

Single Sign-On

Ticket Number: ​INC0027805
Problem Number: ​PRB0010110
Major Incident Number: ​MIR0001066
What happened?

The Single Sign­On service was presenting users with a message indicating that the connection was not private.

Who was affected?

All users attempting to login with a Single Sign­On were affected by this degradation

What was the impact?

The affected users were receiving a message indicating the connection was not private when logging into University of Alberta sites that use the Single Sign­On service for authentication.

What was the timeline of the incident?

Start: 2015/05/07 11:20 – IST began investigating reports of users receiving messages indicating the connection is not private when using the Single Sign­On service.
2015/05/07 11:40 – IST obtained the new security certificate and began uploading to the affected service.
End: 2015/05/07 11:45 – Upload was completed and service was restored.

What was the root cause of the incident?

The Secure Sockets Layer (SSL) Certificate for weblogin.srv.ualberta.ca expired.

What was the work around and resolution for the incident?
Work Around

Users temporarily accepted the warnings presented by web browsers so they could still access sites.



Resolution

The SSL Certificate was updated.

What are any recommendations to prevent this incident from occurring again?
  • Enhance monitoring to look for SSL Certificates warnings.
  • SSL Certificate warnings should be escalated immediately.
Updates

Not Applicable