This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
  • Sebastian, wo hast Du daß gesehen/gehört?  Muß sagen - das stört mich.

    My experience is that there has been a real improvement in Support over the last year and that it's finally at least as good as what we were getting from Astaro. 

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    BAlfson said:
    Muß sagen - das stört mich.

    the same for me, can´t really believe this. But from the Real live perspective, If somebody would ask me, if I can agree with that statement, I would says yes. Just a short sum up of the last view major issues: See all the bugs in 1.) Sandstorm, 2.) scanning within compressed mail attachements, announced for 9.3, was not working (our customer found out), 3.) STAS--> Sophos has really no idea, how it works. It´s full of bugs without and not working properly in HA-mode, there´s even no concept for snycing the stas data between the nodes, it is not part of the sync. Means firewall does a failover and user based firewall rules are not working any more. 4.) Whats with all the FAILED updates with major impact? If we would sum up all of them, I think the list will be long 5.) I have also numerous other tickets, where it becomes clear, that in some cases, there is really bad documentation and even knowledge from sophos emloyees about a feature or functionality.

     

    Back to topic:

    The statement that I mentioned came from our distributor, when I talked to them last week regarding fixing the AD/SSO problem. Today I asked for more details about that statement. The contact at our distributor told me, that he got in touch with this statement two times. One time he heard this from a colleague of him, who was informed about this on one of the roadshows in 2017. The next time, he heard this himself while speaking to a sales territory manager. It was clearly said, that this is officical and thus can be communicated to partners (like us). But he wants to ask for clarification again at sophos.

     

     

    BR

    Sebastian

     

  • Over 20 years in the business

    This is one of the worst perfomances ever

  • We have just been sent a link to 9.502.  Will report back after installation. (We had the rpm patch installed [8110] but still had some authentication issues.)

  • Hi,

     

    I can´t really see any SSO related bug IDs.... Especially not the three ones responsible for the problems (afaik): IDs NUTM-7960, NUTM-8110 and NUTM-8117. Does anyone else do? And will there be also an update for 9.414?

     

    Up2Date Information

    News

    • Maintenance Release
    • Configuration will be upgraded
    • Connected REDs will perform firmware upgrade
    • Connected Wifi APs will perform firmware upgrade

    Remarks

    • System will be rebooted

    Bugfixes

    • NUTM-8127 [AWS] Link to CloudFormation console during cloudupdate is not working
    • NUTM-3213 [Access & Identity] Inconsistent behaviour/state when deleting a user cert
    • NUTM-3283 [Access & Identity] IPSec: VPN ID shall not include blanks
    • NUTM-3294 [Access & Identity] Menu option (keyboard layout) background not rendered properly in IE (version 11.0.9600.17728)
    • NUTM-6972 [Access & Identity] SSLVPN disconnection: backend AD sync
    • NUTM-7897 [Access & Identity] Argos doesn't start in HA setup without IP address
    • NUTM-7940 [Access & Identity] Client Authentication daemon crashes in HA scenario
    • NUTM-7982 [Access & Identity] SSL VPN connection not possible since v9.5 if organisation name contains umlauts
    • NUTM-7996 [Access & Identity] Devices authenticated via SAA are no longer associated with multiple user network objects in UTM 9.5
    • NUTM-8122 [Access & Identity] L2TP connections with separate DHCP server does not work
    • NUTM-8146 [Access & Identity] PPTP fails to connect when Assign IP addresses by is set to DHCP Server
    • NUTM-8147 [Access & Identity] OpenVPN vulnerabilities
    • NUTM-8161 [Access & Identity] OpenVPN vulnerabilities (client part)
    • NUTM-8280 [Access & Identity] High confd load through UMA
    • NUTM-8130 [Basesystem] Linux vulnerability 'The Stack Clash'
    • NUTM-8156 [Basesystem] Apache httpd vulnerability (CVE-2017-3169)
    • NUTM-7235 [Confd] READONLY user can download support package
    • NUTM-7425 [Email] Emailenc causing high load - permanently 100% CPU usage
    • NUTM-7790 [Email] Restrict long regular expression in WebAdmin
    • NUTM-7876 [Email] POP3 Proxy stops working after some time
    • NUTM-7889 [Email] Sandbox scan doesn't work - worker_do_get_file req content parsing error or missing parameters
    • NUTM-6116 [Network] Service_monitor sets wrong IP address for availability group
    • NUTM-7647 [Network] WAN random disconnects
    • NUTM-7735 [Network] ATP doesn't work with "Send anonymous application accuracy telemetry data" disabled.
    • NUTM-7950 [Network] Dhcp client not running - restarted
    • NUTM-8015 [Network] Main interface IP address swapped by additional address for DHCP setup
    • NUTM-7543 [Reporting] Calculate correct malware count for ExecReport
    • NUTM-7609 [Reporting] Websec-reporter is constantly restarting
    • NUTM-7725 [Reporting] High latency while navigating through WebAdmin after trying to display Web Reports
    • NUTM-7878 [WAF] Segfault for HTTP 1.0 requests when cookie rewriting is enabled
    • NUTM-6845 [Web] https://sslvpn.goodix.com does not loads through UTM PROXY
    • NUTM-7467 [Web] Sandstorm communication issues in some configurations
    • NUTM-7697 [Web] httpproxy.ConfdReload - core dump generated during configuration reload
    • NUTM-7895 [Web] Enable SMB2 in Samba
    • NUTM-7939 [Web] Chrome v58 and higher fail verification with HTTPS scanning enabled
    • NUTM-7967 [Web] httpproxy coredump
    • NUTM-6950 [WiFi] APs displayed as inactive in WebAdmin while clients connect to SSIDs which are still being broadcasted
    • NUTM-7495 [WiFi] Wireless client IP in Webadmin not updated after changing the SSID
    • NUTM-6646 [AWS, REST API] REST API panic when unlocking unlocked mutex
    • NUTM-7962 [WiFi] Split traffic not working for wireless clients on RED15w after upgrade to v9.5
  • LEt us all know... so this sounds like the GA pre-release.... 

    Can you confirm and/or update on functionality after install

    THANKS!!!

  • Post has been updated with 7960 and 8110.

    Thank you,

    Bob

  • Thanks Bob...

    So will it show up in UP2DATE or is it currently a manual download?

    Is there any known issues that remain or are created by this newest firmware (that you are aware of)?

    Thanks!

     

    PS Been waiting on fix for SSO authentication ..... currently running 9.501

  • Currently just FTP but will eventually go via Up2Date!

  • Hi all,

    it looks like a new Software is available:

    https://community.sophos.com/products/unified-threat-management/f/hardware-installation-up2date-licensing/93895/utm-9-502-soft-release/339929

    --> SSO Patch is included.

    i´ll give it a try next week.

    Regards

    Martin