This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
  • Thank you Martin!

    Did you have some feedback?

    We are going to test the patch today.

  • I downloaded the update from FTP last night and installed.

    Re-joined the domain and everything seems to be back to normal now.  

    Be sure to go in and use an invalid password to join domain.. this will actually remove the firewall from domain (if you haven't already)...... Then use correct username/password to join domain.  Afterwards I flushed the authentication cache (dont know if that was necessary or not) just to make sure.

    I'll report if anything is noticed in the next few days.... but now now looks good.

     

    Thanks!

    Stafford

  • Thx for your Update Stafford

    When you give a GO I will update also ;)

     

    Tom

  • We've applied the patch in one of ours UTM's and, as says above, the problem seems fixed in version 9.502 . We are rolling on the update in our customers and hope to find no major problems.

    I will post any update.

    Regards,

  • Applied also in two customers UTM and up until now, everything seems to be fixed.

  • Hi guys,

     

    could somebody please tell me, if a SSO Fix Up2Date Package for 9.414 will be available and if yes, when??? And if no, I would like to know why....

  • After Up2Dating to 9.502, I'm no longer able to login to WebAdmin or the User Portal.  I checked things from the command line and I should be having no problems.  I submitted a ticket and have requested escalation.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I guess that has also taken your wireless hotspots down too?

    We keep on having to restart the httpd service as ours crashes once or twice a day but we have been having this issue for ages.

  • Thank you for the feedback Bob

    Let us know about theirs analysis please.

  • Hi Bob,

    we are having the same issue. Authentication gets lost and we have to manually rejoin the utm. Then it works.

    Yesterday i followed the above instructions and edit the crontab-static and after rebuild the entry was found in the crontab as expected. After that i did a reboot just to see if authentication still works (assuming that a reboot would break ad sso authentication and the crontab will handle it). AD Authentication worked fine after reboot.

    This morning the ad sso authentication was broken again. I just looked at the crontab and the line

    0 7 * * * root /usr/local/bin/confd-client.plx ad_join_domain DOMAIN.LOCAL adminbob G3d0utahere! 172.16.1.5

    was gone. Am i missing something? I'm fairly new to sophos, but the changes made to the utm were clear and pretty straight forward for me.

    we are using 2 sg230 in an active / passiv mode, running 9.414-2.

    Dennis