View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0000678 | AlmaLinux-9 | webkit2gtk3 | public | 2026-09-25 15:55 | 2026-09-25 16:29 |
| Reporter | eden91 | Assigned To | |||
| Priority | normal | Severity | major | Reproducibility | always |
| Status | new | Resolution | open | ||
| Platform | x86_64 | OS | Almalinux 9 | OS Version | 9.8 (Olive Jagua |
| Summary | 0000678: webkit2gtk3 2.54.0 breaks Cisco Secure Client SAML/SSO authentication — window goes blank after credential submission (post-redi | ||||
| Description | The SAML/SSO login window opened by Cisco Secure Client's acwebhelper component fails partway through authentication. OS: AlmaLinux 9.x (also reproduced on a fresh AlmaLinux 9 install) Package: webkit2gtk3-2.54.0-1.el9_8.x86_64 / webkit2gtk3-jsc-2.54.0-1.el9_8.x86_64 Application: Cisco Secure Client 5.1.14.145 (Linux, RPM predeploy install) Working reference system: AlmaLinux 8, webkit2gtk3-2.52.5-1.el8_10, same Cisco Secure Client version — works correctly | ||||
| Steps To Reproduce | 1 - Install Cisco Secure Client 5.1.14.145 on AlmaLinux 9 with webkit2gtk3 2.54.0 installed. 2 - Launch vpnui, initiate a connection to a gateway configured for SAML/SSO authentication (identity provider: Google Workspace). 3 - acwebhelper opens the "Cisco Secure Client - Login" window. The login form renders correctly and credentials can be entered normally. Submit/validate the credentials. Expected result: After successful IdP authentication, the SAML redirect completes and the VPN session establishes. Actual result: Immediately after credential validation (the redirect back from the IdP), the window goes completely blank. No error is shown in the window; no relevant error is logged by acwebhelper or csc_ui. The process remains alive indefinitely; authentication never completes on its own. | ||||
| Additional Information | Workaround confirmed: Downgrading both packages resolves the issue immediately: dnf downgrade webkit2gtk3-2.52.5-1.el9_8 webkit2gtk3-jsc-2.52.5-1.el9_8 --allowerasing Thanks for your help ! | ||||
| Tags | No tags attached. | ||||
|
|
Sorry, one missing piece of information: Once I enter my Gmail email address and password, the second step is 2FA — and it's at this step that the window goes blank (no 2FA instructions shown, and no push notification received on my mobile app, Duo Mobile). With webkit2gtk3-2.52.5-1.el9_8, the 2FA instructions appear correctly after the Google authentication step, and I receive the push notification on Duo Mobile. After validating it, the VPN connection is established. Thanks! |