This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
  • I just got off the phone with a 2nd-level tech working on a different issue for me.  He mentioned that all everyone is doing right now is applying patches.  He said there are two different ones.  If the patch you got isn't working, re-open the case and ask if the other patch would be better for you.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • @BAlfson, Does either patch address the transparent SSO authentication that the update broke?  AND does the patch break other stuff so it would be better to wait on the next rev?   Sorry to ask you... but you seem to be better informed than most folks have gotten out of Sophos theirselves.... 

     

    Thanks!

  • @BAlfson

    Thx for your effort and input.

    Your cron job saved my mornings ;)


  • So I installed Firefox - it pops up a dialogue box and I enter my AD credentials and everything works.  Even in IE and Chrome.  Web Filter logs show my credentials correctly and I am being filtered correctly.

    Last night I ran up a VM and reverted to 9.413-4.1.  That was borked too - popping up authentication boxes every that wouldn't accept any credentials..

    So frankly I don't know what is going on.  So little sleep and so much stress from users and management (understandably) that I can't think my way out of a paper bag!

    I think I am just going to try rolling the Sophos Agent out - it works fine on the macs so I will see if it works on PCs..

    Sophos still not responding to emails.

  • Last post on this for me for now..

    Sophos Agent is pretty useless in a place with loads of PCs and users as the MSI installs to the user's appdata\local.  Can't be done quickly without thought and due process.

    So we have reverted back to browser based authentication (and the issues that has) so at least our users can actually access the web.  We had the embarrassment of having to take classes to another local school just so they could take an online test.  

    Absolutely fed up.

  • Don't worry! As you use "The Ultimate Security Package" which is "simpler, faster, better" you have just to wait two to three weeks more to get an emergency hotfix provided over Up2Date. Show stopper bug, and you have to wait four or five weeks to be fixed. Ridiciolous Sophos, and not the first time.

    As I do, you should never use the latest firmware on any productive system. Except there is really a massive security bug which makes UTMs to prefered targets. Let others be the idiots.

    Maybe this patch politics is subtile push for XG? Because of the old old architecture of UTM the bug was overseen and can only be fixed in weeeeeks. Our company will not extend premium support, simpy not worth the money. Nothing premium and shitty support and never helped on any problem.

  • WTF??

    So we should be doing debug for sophos?

    Support already applied two patches and the same issue happens!!!

    First BUG 8110. Ok let's patch it. Nothing solved

    Ahh ok. because of this pactch another bug arise ""UTM-7960". (What?!?) Ok. tet's patch it...  Same thing...

    Next .. Ok. Let's capture data .. some TCPDUMP's, wiresharking.......  Ok stop!! ticket closed. Rolled back to 414.

    Lost a lot of configs, a lot of data but everything is back to normal!!!! Man... 3 fuc.... weeks !!!!! Everybody complaining that authentication fails and can't browsing, etc, etc .... I switched of authentication, and then everyone's able to browsing, but authentication, reports on users, gone .....

     

     

     

     

     

     

  • I learned in this 3 weeks

    blame your reseller and maybe if we are lucky there is an update in the middle of July (but its topsecret) HAHAHAHAAHAH ;)

     

  • Stafford, I have no personal experience with any of this as I've done my best to keep everyone on 9.413.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA