# Client reconnect conditions for SSO and Device auth

**URL:** <https://forum.pritunl.com/t/client-reconnect-conditions-for-sso-and-device-auth/3243>\
**Category:** Pritunl VPN\
**Tags:** pritunl\
**Created:** [April 16, 2025, 1:22pm UTC](https://forum.pritunl.com/t/client-reconnect-conditions-for-sso-and-device-auth/3243 "2025-04-16T13:22:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrii](https://forum.pritunl.com/user_avatar/forum.pritunl.com/andrii/32/1194_2.png) [@andrii](https://forum.pritunl.com/u/andrii)\
**Post date:** [April 16, 2025, 1:22pm UTC](https://forum.pritunl.com/t/client-reconnect-conditions-for-sso-and-device-auth/3243/1 "2025-04-16T13:22:30Z")

</div>

Hi,

I am trying to digest under which conditions the client reconnect (for Pritunl client) is enabled.

According to the code [pritunl/pritunl/clients/clients.py at master · pritunl/pritunl · GitHub](https://github.com/pritunl/pritunl/blob/master/pritunl/clients/clients.py#L134) the ping-exit instead of ping-reconnect is used in particular when `server.sso_auth` is enabled.

However I have the `app.sso_client_cache` for Pritunl client enabled as well, so having SSO auth enabled should not block reconnect technically.

Seams changing condition to `( self.server.sso_auth and not settings.app.sso_client_cache )` will be more reasonable.

Also `self.server.device_auth` is blocking reconnect as well. Any reasons why it is designed like this?

Appreciate your thoughts on it.  
I think if logic will be altered to make it work for device and sso auth with pritunl client - this makes UX better.

Best regards,  
Andrii

---

<div class="post-metadata">

**Author:** ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)\
**Post date:** [April 16, 2025, 7:36pm UTC](https://forum.pritunl.com/t/client-reconnect-conditions-for-sso-and-device-auth/3243/2 "2025-04-16T19:36:02Z")

</div>

That code determines how the OpenVPN configuration exits, it doesn’t control if a re-connection is attempted in the Pritunl Client. It’s only for older versions of the client and third party OpenVPN clients. The Pritunl Client will always use `ping-exit`. Reconection on the Pritunl Client is determined by `disable_reconnect` in [**pritunl/user/user.py**](https://github.com/pritunl/pritunl/blob/master/pritunl/user/user.py#L867). It is only disabled when done with the global option in the top right settings and if the server uses a session timeout.

---

<div class="post-metadata">

**Author:** ![andrii](https://forum.pritunl.com/user_avatar/forum.pritunl.com/andrii/32/1194_2.png) [@andrii](https://forum.pritunl.com/u/andrii)\
**Post date:** [April 17, 2025, 7:16am UTC](https://forum.pritunl.com/t/client-reconnect-conditions-for-sso-and-device-auth/3243/3 "2025-04-17T07:16:19Z")

</div>

Thanks a lot for a prompt reply! Indeed, I was looking into wrong direction, the user session timeout makes it! Just re-tested with both SSO and Device Auth.

Would you consider adding a few words like “Disables client reconnect” to option description here: [pritunl/www/templates/modalServerSettings.html at master · pritunl/pritunl · GitHub](https://github.com/pritunl/pritunl/blob/master/www/templates/modalServerSettings.html#L125) ?

At least for me it was not obvious and I think it will be beneficial to have a notice like this to minimize confusion 🙂

---

<div class="post-metadata">

**Author:** ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)\
**Post date:** [April 17, 2025, 9:54pm UTC](https://forum.pritunl.com/t/client-reconnect-conditions-for-sso-and-device-auth/3243/4 "2025-04-17T21:54:54Z")

</div>

That tooltip will be updated in the next release.
