This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
  • Jorge,

    Man, I'm sorry you're having to deal with all that!

    I do very little debugging for Sophos outside of when I participate in a beta.  One of the reasons I help home-use licensees for free here is that I want them to discover the glitches before my clients do.  There will always be a few businesses with too little experience that will put on the latest firmware, so I also consider them a lab for my clients.  I won't even put 9.5 in my lab yet.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • If Sophos is so horrible/incompetent at testing their updates that you need to do that then something is seriously wrong. What if everyone took that advice? Then no one would update and we'd all stare at each other like we're in some kind of weird Mexican standoff waiting for the other person to move first. The real solution here is for Sophos to actually hire and use competent developers and software Q/A techs instead of pushing out half-baked, Alpha quality updates.

  • Blake, I've been in this business for 40+ years.  This has always been the approach that's taken with complex products.  This is not a spreadsheet managed and modified by one person.  How many updates on apps in your iPhone don't mention fixing bugs?  Is this software more or less complex than those apps?  Did you see my story about my wife and the IBM SVC in front of her organization's hundreds of virtualized terabytes?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Update:

    Sophos applied the RPM Package on Wednesday, we had to reboot the cluster and rejoin the domain. Everything is working properly now.

    We got told that there should be an official update via Up2Date in calender week 28.

  • Patched today - rebooted UTM, ran "/usr/local/bin/ntlm_resync.pl"

    Reverted to AD SSO from Browser based authentication and instantly fixed.

    So mixed feelings here but glad we are sorted.

     

    Thanks to everyone on here for the advice.

  • I can also confirm that after 3 weeks, i got the machines patched and it´s working.

  • Hi,

    We are experiencing the same  ISSUE, Sophos supports says that the patch will be available this week, but, in the meantime, no other solutions were provided.

    Cand somebody share the RPM that was applied by the "Super" Sophos Support team?

    Thanks.

  • Dont know if this is what you are looking for... but I had a tech look at my machine because another told me that a patch was available.

    This 2nd or 3rd level tech told me there was initially 2 patches... related to the same thing but addressing different isues with the SSO.  If the techs are telling them there is not a patch is it because this person told me there WAS two patches.  One was pulled because it caused more problems... and that I would have to wait for the actual next release instead of an RPM patch.

    So.. probably Rodrigo has the issue that cannot be fixed at this time.

    Dont shoot the messinger.. Im just relaying what I have been told.

    Thanks..... 

  • Thanks for your answer, that was very helpful.

    So, with no other options, I think that we are going to take our customers back to 9.413-4 and wait for Sophos to release a new update, at least, until our customers kill us first...

    Regards,

  • Hi Thorsten,

    some comments, I would like to share about what you said, Im pretty much feeling the same:

     

    Thorsten Langer said:
    Ridiciolous Sophos, and not the first time.

    Yes, I absolutely with this, we are facing this bad QS and in general often bad support quality for about 3 Years now. I mean, sometimes it´s ok/good, but the most time, it´s really astonishing, how bad this support is.

     

    Thorsten Langer said:
    Our company will not extend premium support, simpy not worth the money. Nothing premium and shitty support and never helped on any problem.

    I´m also tending to not sell "premium support" any more, simply because it is not that, what its labeled as. As we are able to work with our distributor, we prefer this, they can also create tickets with higher priorisation.

     

    Probably you and the most of the members here won´t know it, this week I heard, that sophos officially anounced their politics/philosopy to their products, especially for UTM (and this is no Joke), Attention please, the sentence is analogous to what they said:

    In Deutsch:

    „Sophos Firmenpolitik zielt darauf ab möglichst mit vielen neuen Features auf den Markt zu drängen. Dabei ist die tatsächliche Funktion nebensächlich.“

     

    English:

    "Sophos´s philosophy is to become market leader in providing new features in their software, but that they really work is minor."

     

    Ok, now we now, it´s not a bug, it´s a feature, it´s their politics....

     

    BR

    Sebastian