Skip to main content
NetApp Knowledge Base

Workload Security UI shows Token has expired

Views:
Visibility:
Public
Votes:
0
Category:
data-infrastructure-insights
Specialty:
ds_dii
Last Updated:

Applies to

  • Data Infrastructure Insights (DII)
  • Storage Workload Security (SWS)

Issue

  • Workload Security UI shows error Token has expired (example: Token has expired on <date> at <time>)
  • All Workload Security agents appear missing from the UI
  • All Workload Security data collectors appear missing from the UI
  • User Forensics fails with a token expired error
  • Other areas of Data Infrastructure Insights continue to work normally
  • The issue may clear after a new login session

Cause

  • Workload Security UI uses short-lived JSON Web Tokens (JWTs) that expire after about 7 minutes
  • The UI refreshes the JWT about every 5 minutes by calling the Gateway /authorize endpoint
  • A transient HTTP 500 response from the Gateway /authorize endpoint prevents the JWT refresh
  • The Workload Security UI does not retry the /authorize call after that transient failure
  • With an expired JWT, the UI cannot load agents, collectors, or User Forensics and displays Token has expired until a new login obtains a fresh token

Solution

  1. Workaround: Log out of Data Infrastructure Insights and log in again to obtain a new Workload Security JWT
  2. Confirm Workload Security agents, collectors, and User Forensics load successfully after re-login
  3. If the issue returns after re-login, open a case with NetApp Support and include the tenant URL, approximate time of the error (with timezone), and screenshots of the Token has expired message
  • Note: Engineering is tracking a product fix so the Workload Security UI retries JWT refresh after a transient /authorize failure

Partner Notes

partnerNotes_text

Additional Information

Internal Notes

  • Derived from case 2010768824 / ICI-19343
  • Engineering RCA: SWS UI JWTs are short-lived (~7 min) and refreshed every ~5 min via Gateway GET /rest/v1/csecure/<id>/authorize. Transient Gateway HTTP 500 blocked refresh; UI did not retry. Next login session recovered.
  • Jira: ICI-19343 (follow-on bug for UI auto-retry planned by engineering; add public report link in Cause/Solution when available)
  • Tenant example pattern (do not publish customer IDs): Gateway authorize under /rest/v1/csecure/<tenant_or_context_id>/authorize

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.