Skip to content

Incident detail

OIDC tls_client_auth_ssl_verify field defaulted to `false` for new updates not explicitly setting the property

Resolved incidentMinor1 affected service

Timeline window

to

Get alerted the next time Kong breaks

Free email alerts for the handful of vendors you cannot afford to miss. No card, live in about a minute. Paid plans add Slack, Teams, Discord, and webhook delivery across your whole stack, plus higher API quotas.

Timeline

Incident updates

Every update Kong posted, oldest to newest, exactly as it appeared on their official status page.

  1. Resolved

    Customers running 3.13 and below who use the OIDC plugin with `tls_client_auth_ssl_verify` unset would have seen this value change to `false` if they updated the config after the rollback of new defaults following the 3.14 release.

    The rollback incorrectly flipped the oidc plugin tls_client_auth_ssl_verify to false as a default, which was not one of the items recently switched to default true and has instead been defaulted true for some time.

    We have rolled out a fix to prod to change this default back to true. Updates to the OIDC plugin should once again keep this value set to true if not specifically defined.

Keep exploring

More from Kong

Neighboring incidents on Kong's timeline and the rest of their record on OutageDeck.