This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
  • Dennis, /etc/crontab gets overwritten often - you must add that line in /etc/crontab-static and it will then be included in crontab when you make any change in WebAdmin that affects a cronjob.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • We now have 9.502 installed and still have issues with service accounts accessing the internet (giving account lockouts.)

  • We have applied the update today and everything seems to be working.

  • That's what i did. I add the line in the crontab-static, then made changes to the webadmin and the crontab was updated. Today both, the /etc/crontab-static and etc/crontab were missing the line i added yesterday. All i did was the reboot. Is it possible, that the changes made interfere with the acticv-passive cluster?

     

    Dennis

  • We had the same problem, and we resolved it by doing this:

    • Re-join the UTM with a bad account (un-join the domain)
    • Remove the UTM object from the AD
    • Join the UTM with correct credentials

    For the moment, the SSO is working and no other problems were detected.

     

    Regards

  • I've installed 9.502 yesterday and rejoined domain. SSO authentication was still working this morning...

    ...but only in proxy mode, transparent mode with SSO is broken.

  • So far all good here. I installed 9.502 last night. Rejoined with wrong password and then rejoined AD with correct password. No messing with object in ADUC. Then re-enabled Active Directory SSO on the networks in Tranparent Mode.

    When the problem started all I ended up doing was set the Default Authentication method to "none" and then change my "Unlimited internet access" policy to include all users. Now all users was getting used to having unlimited internet access and they were disappointed to have limited access this morning, but no auth problems :)

    All my networks are in Transparent Mode.

    Only Session Host Servers have proxy set in Internet Settings via GPO

    Haven't had any issues today on any machines so all seem to be working just fine.

    I did however reboot all servers including DCs last night.

  • In HA, changes at the command line must be made to both devices.  Apparently, you're now working on what was the Slave when you changed /etc/crontab-static.  Just do the same thing on the current Master and you'll be good to go on either device.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • We have been told there is an issue with complex passwords which will be fixed in 9.503 (and now I'm awaiting release date information.)

  • Do you know what the definition of "complex" is related to this error? Just special characters or problems with upper/lower/numbers/length?