This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
Parents
  • We have some customers with the same problem.

    Tried the solution: disjoin A.D., delete AD-account, Sync AD's, rejoin UTM to AD and resume SSO authentication: this works for a a day or less.

    Now I see in the http-log this error several times :

    2017:06:21-07:56:07 UTM01-2 httpproxy[13006]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0xff1d600" function="adir_auth_process_negotiate" file="auth_adir.c" line="1636" message="gss_accept_sec_context: Key version number for principal in key table is incorrect"

     

    For now, SSON authentication is disabled ...

Reply
  • We have some customers with the same problem.

    Tried the solution: disjoin A.D., delete AD-account, Sync AD's, rejoin UTM to AD and resume SSO authentication: this works for a a day or less.

    Now I see in the http-log this error several times :

    2017:06:21-07:56:07 UTM01-2 httpproxy[13006]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0xff1d600" function="adir_auth_process_negotiate" file="auth_adir.c" line="1636" message="gss_accept_sec_context: Key version number for principal in key table is incorrect"

     

    For now, SSON authentication is disabled ...

Children
No Data