Tech note: Tomcat in-place upgrades to version 10.1.58 or later🔗
Performing an in-place Apache Tomcat upgrade to version 10.1.58 or later silently disables OpenID Connect (OIDC) single sign-on (SSO) in Matillion ETL. No error is logged on the server when this happens; SSO simply stops working. This tech note explains why, how to recognize it, and what to do about it.
What this applies to🔗
This affects every currently released Matillion ETL version when the Tomcat it runs on is upgraded in place, independently of a Matillion ETL release, to Tomcat version 10.1.58 or later.
Tomcat and Matillion ETL are versioned and upgraded independently, and the Tomcat version in use isn't tied to a specific Matillion ETL release. No currently released Matillion ETL version contains the fix.
Symptoms🔗
Clicking OIDC Login with ... on the Matillion ETL login page fails with a 500 Internal Server Error, with no further explanation shown to the user.
Nothing unusual appears in Tomcat's logs, even at the default log level. This is not a crash: the authenticator code simply never runs, so there is nothing for it to log.
The symptom appears only after Tomcat itself (not Matillion ETL) has been upgraded independently to version 10.1.58 or later. A Matillion ETL instance that has not had its Tomcat upgraded this way is unaffected.
Other authentication methods (local username/password) continue to work normally; only OIDC SSO is affected.
Root cause🔗
Apache Tomcat 10.1.58 changed how it internally dispatches requests through authenticator components. Matillion ETL's OIDC integration was written against Tomcat's older behavior, so when Tomcat alone is upgraded past that version, Tomcat routes requests through a path that bypasses Matillion ETL's OIDC logic entirely. SSO stops functioning, but because nothing actually fails or throws an error—from Tomcat's point of view, the request is handled normally—no error is logged anywhere.
Recommended action🔗
Before upgrading: Until a fix for this is available, do not upgrade Tomcat on a Matillion ETL instance independently of a Matillion ETL release if OIDC SSO is in use. If SSO has already broken after an in-place Tomcat upgrade: There are two options to restore access immediately:
- Recommended: Revert the Tomcat upgrade to a version below 10.1.58. This restores the authenticator dispatch behavior that Matillion ETL's OIDC code expects, and SSO works again immediately, with no change to your OIDC configuration.
- If reverting isn't immediately possible: You can restore login access without touching Tomcat. In the Matillion ETL Admin menu, go to User Configuration and set the security type to Internal (no OIDC provider). This restores username/password login, but disables OIDC SSO until you revert Tomcat or the fix ships.
You should upgrade to the fixed Matillion ETL version once it's available.
Resolution🔗
A fix is in progress and will be included in the next Matillion ETL release.
This tech note will be updated with the details of the fixed version once that release is available.