Hello! We have many windows users reporting that immediately after upgrading Viscosity to 1.13, the SSO login page hangs and eventually times out after our time limit. And I’m able to reproduce this issue on my windows machine as well.
For context, we use Okta as our SSO in additions to Kolide as the device trust tool where our okta authentication policy requires Kolide to perform a series of checks to make sure the local machine satisfies all requirements (like if everything is up to date). It looks like within the webview, it’s not able receive Kolide’s pass/fail signal (or something gets silently dropped) and hangs forever until it times out.
Here are my viscosity logs:
Jul 16 5:12:20 PM: State changed to Connecting
Jul 16 5:12:20 PM: Viscosity Windows 1.13 (1877)
Jul 16 5:12:21 PM: Running on Microsoft Windows 11 Pro 64 bit
Jul 16 5:12:21 PM: Running on .NET Framework Version 4.8.09221.533509
Jul 16 5:12:21 PM: Checking reachability status of connection...
Jul 16 5:12:21 PM: Connection is reachable. Starting connection attempt.
Jul 16 5:12:21 PM: Interface Type: ViscTunTap
Jul 16 5:12:21 PM: No associated network adapter was found, creating one. This process may take up to a minute or two.
Jul 16 5:12:21 PM: Current Parameter Settings:
Jul 16 5:12:21 PM: config = 'stdin'
Jul 16 5:12:21 PM: mode = 0
Jul 16 5:12:21 PM: show_ciphers = DISABLED
Jul 16 5:12:21 PM: show_digests = DISABLED
Jul 16 5:12:21 PM: show_engines = DISABLED
Jul 16 5:12:21 PM: genkey = DISABLED
Jul 16 5:12:21 PM: genkey_filename = '[UNDEF]'
Jul 16 5:12:21 PM: key_pass_file = '[UNDEF]'
Jul 16 5:12:21 PM: show_tls_ciphers = DISABLED
Jul 16 5:12:21 PM: connect_retry_max = 1
Jul 16 5:12:21 PM: Connection profiles [0]:
Jul 16 5:12:21 PM: proto = udp
Jul 16 5:12:21 PM: local = '[UNDEF]'
Jul 16 5:12:21 PM: local_port = '[UNDEF]'
Jul 16 5:12:21 PM: remote = 'vpn.example.com'
Jul 16 5:12:21 PM: remote_port = '1194'
Jul 16 5:12:21 PM: remote_float = DISABLED
Jul 16 5:12:21 PM: bind_defined = DISABLED
Jul 16 5:12:21 PM: bind_local = DISABLED
Jul 16 5:12:21 PM: bind_ipv6_only = DISABLED
Jul 16 5:12:21 PM: connect_retry_seconds = 1
Jul 16 5:12:21 PM: connect_timeout = 120
Jul 16 5:12:21 PM: socks_proxy_server = '[UNDEF]'
Jul 16 5:12:21 PM: socks_proxy_port = '[UNDEF]'
Jul 16 5:12:21 PM: tun_mtu = 1350
Jul 16 5:12:21 PM: tun_mtu_defined = ENABLED
Jul 16 5:12:21 PM: link_mtu = 1500
Jul 16 5:12:21 PM: link_mtu_defined = DISABLED
Jul 16 5:12:21 PM: tun_mtu_extra = 0
Jul 16 5:12:21 PM: tun_mtu_extra_defined = DISABLED
Jul 16 5:12:21 PM: tls_mtu = 1250
Jul 16 5:12:21 PM: mtu_discover_type = -1
Jul 16 5:12:21 PM: NOTE: --mute triggered...
Jul 16 5:12:21 PM: 252 variation(s) on previous 100 message(s) suppressed by --mute
Jul 16 5:12:21 PM: OpenVPN 2.6.21 Windows [SSL (OpenSSL)] [LZO] [LZ4] [AEAD]
Jul 16 5:12:21 PM: library versions: OpenSSL 3.5.7 9 Jun 2026, LZO 2.10
Jul 16 5:12:21 PM: Resolving address: "vpn.example.com"
Jul 16 5:12:22 PM: Valid endpoint found: vpn.example.com:1194:udp
Jul 16 5:12:22 PM: Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Jul 16 5:12:22 PM: Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Jul 16 5:12:22 PM: Control Channel MTU parms [ mss_fix:0 max_frag:0 tun_mtu:1250 tun_max_mtu:0 headroom:126 payload:1600 tailroom:126 ET:0 ]
Jul 16 5:12:22 PM: Data Channel MTU parms [ mss_fix:0 max_frag:0 tun_mtu:1350 tun_max_mtu:1600 headroom:136 payload:1768 tailroom:562 ET:0 ]
Jul 16 5:12:22 PM: TCP/UDP: Preserving recently used remote address: [AF_INET]203.0.113.10:1194
Jul 16 5:12:22 PM: Socket Buffers: R=[65536->65536] S=[65536->65536]
Jul 16 5:12:22 PM: UDPv4 link local: (not bound)
Jul 16 5:12:22 PM: UDPv4 link remote: [AF_INET]203.0.113.10:1194
Jul 16 5:12:22 PM: State changed to Authenticating
Jul 16 5:12:22 PM: TLS: Initial packet from [AF_INET]203.0.113.10:1194, sid=00000000 00000000
Jul 16 5:12:22 PM: VERIFY OK: depth=4, C=US, O=Internet Security Research Group, CN=ISRG Root X1
Jul 16 5:12:22 PM: VERIFY OK: depth=3, C=US, O=Internet Security Research Group, CN=ISRG Root X2
Jul 16 5:12:22 PM: VERIFY OK: depth=2, C=US, O=ISRG, CN=Root YE
Jul 16 5:12:22 PM: VERIFY OK: depth=1, C=US, O=Let's Encrypt, CN=YE2
Jul 16 5:12:22 PM: VERIFY KU OK
Jul 16 5:12:22 PM: Validating certificate extended key usage
Jul 16 5:12:22 PM: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Jul 16 5:12:22 PM: VERIFY EKU OK
Jul 16 5:12:22 PM: VERIFY X509NAME OK: CN=vpn.example.com
Jul 16 5:12:22 PM: VERIFY OK: depth=0, CN=vpn.example.com
Jul 16 5:12:22 PM: Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 256 bits ECprime256v1, signature: ecdsa-with-SHA384, peer temporary key: 253 bits X25519
Jul 16 5:12:22 PM: [vpn.example.com] Peer Connection Initiated with [AF_INET]203.0.113.10:1194
Jul 16 5:12:22 PM: TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
Jul 16 5:12:22 PM: TLS: tls_multi_process: initial untrusted session promoted to trusted
Jul 16 5:12:22 PM: State changed to Connecting
Jul 16 5:12:22 PM: SENT CONTROL [vpn.example.com]: 'PUSH_REQUEST' (status=1)
Jul 16 5:12:22 PM: State changed to Authenticating
Jul 16 5:12:22 PM: AUTH_PENDING received, extending handshake timeout from 60s to 60s
Jul 16 5:12:22 PM: URL authentication request received from server. Attempting to load URL...
Jul 16 5:12:22 PM: Info command was pushed by server ('WEB_AUTH::https://vpn.example.com:443/oauth2/start?state=REDACTED')
Jul 16 5:12:23 PM: SENT CONTROL [vpn.example.com]: 'PUSH_REQUEST' (status=1)
Jul 16 5:12:24 PM: Authentication URL successfully loaded.
Jul 16 5:12:24 PM: SENT CONTROL [vpn.example.com]: 'PUSH_REQUEST' (status=1)
..... goes on for a while
Jul 16 5:12:56 PM: SENT CONTROL [vpn.example.com]: 'PUSH_REQUEST' (status=1)
Jul 16 5:12:57 PM: NOTE: --mute triggered...
Jul 16 5:13:23 PM: 22 variation(s) on previous 100 message(s) suppressed by --mute
Jul 16 5:13:23 PM: No reply from server to push requests in 61s
Jul 16 5:13:23 PM: TCP/UDP: Closing socket
Jul 16 5:13:23 PM: SIGUSR1[soft,no-push-reply] received, process restarting
Jul 16 5:13:23 PM: State changed to Connecting
Jul 16 5:13:23 PM: Restart pause, 1 second(s)
..... restarts another loop
A little bit more context on Kolide:
Kolide’s agent runs a local HTTP server on 127.0.0.1 on a high-numbered port. The Okta login page loaded in Viscosity’s WebView window makes requests to that loopback address to perform device authentication.
Additionally, do we expect windows viscosity to be able open the login page in an external browser soon? This feature has been available in mac for a while now.
Thank you very much!
