11-15-2018 06:30 AM
Is the single click self-registration link that is sent to sponsor in the email PSN specific? I mean can any PSN process that link?
I have a two node deployment where the sponsor portal has an FQDN, sponsor.mycompany.com. We have A records for sponsor.mycompany.com pointing at both ISE nodes. If ISE node #1 processes the self-registration and sends the email, but DNS resolves sponsor.mycompany.com to node #2, the link errors out saying it has expired. If it goes to node #1 it works just fine.
I have used this setup before many times (FQDN with multiple A records) and don't remember this issue.
I am going to test in my lab hopefully this week when I get time.
Solved! Go to Solution.
11-15-2018 08:34 AM
11-16-2018 06:10 AM - edited 11-16-2018 06:11 AM
Okay I just tested this on a different customer and the approval link is not tied to a PSN (whew... I thought I was going crazy). There must be an issue with the 2nd PSN at the customer I saw this issue.
For your reference the Approval link looks like this:
https://sponsor.mycompany.com:8445/sponsorportal/PortalSetup.action?portal=af0e2960-c324-11e8-b505-6a8ec20f675a&oneClickToken=4Hm/OR0mv3/l/xnzMs7b5g==&oneClickAction=Approve
I tested by changing the link to a PSN that didn't do the guest registration:
https://psn05.mycompany.com:8445/sponsorportal/PortalSetup.action?portal=af0e2960-c324-11e8-b505-6a8ec20f675a&oneClickToken=4Hm/OR0mv3/l/xnzMs7b5g==&oneClickAction=Approve
Everything worked just fine. The only part of the string that changes from request to request is the oneClickToken value that isn't PSN specific. I believe, Jason correct me if I am wrong, the value is the encoded AD information of the person being visited.
11-15-2018 06:44 AM
I got same issue in my 2 node deployment. Thats why in Authorization i mark static redirection to 1 psn . And it never send to second .
11-15-2018 06:47 AM
11-16-2018 06:10 AM - edited 11-16-2018 06:11 AM
Okay I just tested this on a different customer and the approval link is not tied to a PSN (whew... I thought I was going crazy). There must be an issue with the 2nd PSN at the customer I saw this issue.
For your reference the Approval link looks like this:
https://sponsor.mycompany.com:8445/sponsorportal/PortalSetup.action?portal=af0e2960-c324-11e8-b505-6a8ec20f675a&oneClickToken=4Hm/OR0mv3/l/xnzMs7b5g==&oneClickAction=Approve
I tested by changing the link to a PSN that didn't do the guest registration:
https://psn05.mycompany.com:8445/sponsorportal/PortalSetup.action?portal=af0e2960-c324-11e8-b505-6a8ec20f675a&oneClickToken=4Hm/OR0mv3/l/xnzMs7b5g==&oneClickAction=Approve
Everything worked just fine. The only part of the string that changes from request to request is the oneClickToken value that isn't PSN specific. I believe, Jason correct me if I am wrong, the value is the encoded AD information of the person being visited.
11-16-2018 06:23 AM - edited 11-16-2018 08:14 AM
Paul you're correct, the token is for the approval session authentication that includes the guest account
11-15-2018 08:34 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide