Description of problem: When using a Mac OS X client (10.11.5) and Safari (9.1.1), Cockpit repeatedly disconnects. relevant journald entries: May 26 15:46:13 gizmo.evilduckie.com audit[5818]: USER_AUTH pid=5818 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:cockpit_session_t:s0 msg='op=PAM:authentication grantors=pam_unix acct="david" exe="/usr/libexec/cockpit-session" hostname=192.168.1.166 addr=192.168.1.166 terminal=? res=success' May 26 15:46:13 gizmo.evilduckie.com audit[5818]: USER_ACCT pid=5818 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:cockpit_session_t:s0 msg='op=PAM:accounting grantors=pam_unix,pam_localuser acct="david" exe="/usr/libexec/cockpit-session" hostname=192.168.1.166 addr=192.168.1.166 terminal=? res=success' May 26 15:46:13 gizmo.evilduckie.com audit[5818]: CRED_ACQ pid=5818 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:cockpit_session_t:s0 msg='op=PAM:setcred grantors=pam_unix acct="david" exe="/usr/libexec/cockpit-session" hostname=192.168.1.166 addr=192.168.1.166 terminal=? res=success' May 26 15:46:13 gizmo.evilduckie.com audit[5818]: USER_ROLE_CHANGE pid=5818 uid=0 auid=1000 ses=12 subj=system_u:system_r:cockpit_session_t:s0 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0 selected-context=unconfined_u:unconfined_r:unconfined_t:s0 exe="/usr/libexec/cockpit-session" hostname=192.168.1.166 addr=192.168.1.166 terminal=? res=success' May 26 15:46:13 gizmo.evilduckie.com cockpit-session[5818]: pam_ssh_add: Failed adding some keys May 26 15:46:13 gizmo.evilduckie.com audit[1]: USER_AVC pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='Unknown permission start for class system exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?' May 26 15:46:13 gizmo.evilduckie.com audit[1]: USER_AVC pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='Unknown permission start for class system exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?' May 26 15:46:13 gizmo.evilduckie.com systemd-logind[1106]: New session 12 of user david. May 26 15:46:13 gizmo.evilduckie.com systemd[1]: Started Session 12 of user david. May 26 15:46:13 gizmo.evilduckie.com cockpit-session[5818]: pam_unix(cockpit:session): session opened for user david by (uid=0) May 26 15:46:13 gizmo.evilduckie.com audit[5818]: USER_START pid=5818 uid=0 auid=1000 ses=12 subj=system_u:system_r:cockpit_session_t:s0 msg='op=PAM:session_open grantors=pam_selinux,pam_loginuid,pam_selinux,pam_keyinit,pam_reauthorize,pam_ssh_add,pam_keyinit,pam_limits,pam_systemd,pam_unix,pam_lastlog acct="david" exe="/usr/libexec/cockpit-session" hostname=192.168.1.166 addr=192.168.1.166 terminal=? res=success' May 26 15:46:13 gizmo.evilduckie.com audit[5818]: CRED_REFR pid=5818 uid=0 auid=1000 ses=12 subj=system_u:system_r:cockpit_session_t:s0 msg='op=PAM:setcred grantors=pam_unix acct="david" exe="/usr/libexec/cockpit-session" hostname=192.168.1.166 addr=192.168.1.166 terminal=? res=success' May 26 15:46:13 gizmo.evilduckie.com cockpit-ws[5708]: logged in user: david May 26 15:46:13 gizmo.evilduckie.com polkitd[1117]: Registered Authentication Agent for unix-session:12 (system bus name :1.68 [cockpit-bridge], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) May 26 15:46:14 gizmo.evilduckie.com cockpit-ws[5708]: couldn't read from connection: Peer failed to perform TLS handshake May 26 15:46:28 gizmo.evilduckie.com cockpit-ws[5708]: david: timed out May 26 15:46:28 gizmo.evilduckie.com polkitd[1117]: Unregistered Authentication Agent for unix-session:12 (system bus name :1.68, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) May 26 15:46:28 gizmo.evilduckie.com audit[5818]: CRED_DISP pid=5818 uid=0 auid=1000 ses=12 subj=system_u:system_r:cockpit_session_t:s0 msg='op=PAM:setcred grantors=pam_unix acct="david" exe="/usr/libexec/cockpit-session" hostname=192.168.1.166 addr=192.168.1.166 terminal=? res=success' May 26 15:46:28 gizmo.evilduckie.com cockpit-session[5818]: pam_unix(cockpit:session): session closed for user david May 26 15:46:28 gizmo.evilduckie.com audit[5818]: USER_END pid=5818 uid=0 auid=1000 ses=12 subj=system_u:system_r:cockpit_session_t:s0 msg='op=PAM:session_close grantors=pam_selinux,pam_loginuid,pam_selinux,pam_keyinit,pam_reauthorize,pam_ssh_add,pam_keyinit,pam_limits,pam_systemd,pam_unix,pam_lastlog acct="david" exe="/usr/libexec/cockpit-session" hostname=192.168.1.166 addr=192.168.1.166 terminal=? res=success' May 26 15:46:28 gizmo.evilduckie.com audit[1]: USER_AVC pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='Unknown permission stop for class system exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?' May 26 15:46:28 gizmo.evilduckie.com systemd-logind[1106]: Removed session 12. Version-Release number of selected component (if applicable): How reproducible: always Steps to Reproduce: 1. install Fedora 24 server 2. access cockpit via a Mac with Safari 3. fail! Actual results: Upon attempting to authenticate, the following message is displayed: "Disconnected Server has closed the connection." Expected results: successful authentication Additional info: Works fine with Chrome (version 51) and Firefox.
Sorry forgot to paste the cockpit version into the ticket: Version : 0.107 Release : 1.fc24
Are you running with self-signed certificates? Safari doesn't allow secure websockets with self-signed certs.
I am. I will try a certificate from Startcom and see what happens.
This package has changed ownership in the Fedora Package Database. Reassigning to the new owner of this component.
(In reply to David Yaffe from comment #3) > I am. I will try a certificate from Startcom and see what happens. Did this work?
This message is a reminder that Fedora 24 is nearing its end of life. Approximately 2 (two) weeks from now Fedora will stop maintaining and issuing updates for Fedora 24. It is Fedora's policy to close all bug reports from releases that are no longer maintained. At that time this bug will be closed as EOL if it remains open with a Fedora 'version' of '24'. Package Maintainer: If you wish for this bug to remain open because you plan to fix it in a currently maintained version, simply change the 'version' to a later Fedora version. Thank you for reporting this issue and we are sorry that we were not able to fix it before Fedora 24 is end of life. If you would still like to see this bug fixed and are able to reproduce it against a later version of Fedora, you are encouraged change the 'version' to a later Fedora version prior this bug is closed as described in the policy above. Although we aim to fix as many bugs as possible during every release's lifetime, sometimes those efforts are overtaken by events. Often a more recent Fedora release includes newer upstream software that fixes bugs or makes them obsolete.
Fedora 24 changed to end-of-life (EOL) status on 2017-08-08. Fedora 24 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora please feel free to reopen this bug against that version. If you are unable to reopen this bug, please file a new report against the current release. If you experience problems, please add a comment to this bug. Thank you for reporting this bug and we are sorry it could not be fixed.
No longer an issue.