This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
  • The best thing Sophos can do for now is release the 9.500 firmware so that we can rollback to the previous version.

    Why is that so hard to do? Is there any logical explanation for this version been removed from the FTP site?  Come'on  guys we're struggling a lot because we have many rules and fastvue reports based on AD authentication.

    Best Regards

    Jorge

  • We have some customers with the same problem.

    Tried the solution: disjoin A.D., delete AD-account, Sync AD's, rejoin UTM to AD and resume SSO authentication: this works for a a day or less.

    Now I see in the http-log this error several times :

    2017:06:21-07:56:07 UTM01-2 httpproxy[13006]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0xff1d600" function="adir_auth_process_negotiate" file="auth_adir.c" line="1636" message="gss_accept_sec_context: Key version number for principal in key table is incorrect"

     

    For now, SSON authentication is disabled ...

  • It doesn't sound like a fix will be coming soon - so I am going to roll back the UTM to version 9.414 - and restore my settings from a backup.  Anyone have any issues doing this?  Be good to know what to look out for.

    Thanks!

  • Becareful with the version 9.414-2. We have the same problem on this firmware.

     

    Best Regards

     

    Kim

     

    Gruß

    Kim Rainer Sparke

  • Thanks - that's the version we were on since last week - and didn't have a problem.  But i'll check that and go back to 9.413 if needed.

  • Hi, Thomas, and welcome to the UTM Community!

    Have you tried a cronjob as suggested in Sophos UTM: Httpproxy with AD-SSO authentication doesn't work with Internet Explorer and Chrome after upgrading to 9.5?

    To do this every morning at 7AM add the following line to /etc/crontab-static (substitute with your credentials):

    0 7 * * * root /usr/local/bin/confd-client.plx ad_join_domain DOMAIN.LOCAL adminbob G3d0utahere! 172.16.1.5

    After that, you need to make the system rebuild /etc/crontab.  In 'Management > Up2Date' change the 'Firmware Download Interval', [Apply], change it back and [Apply].

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • thx  ;)

     

    Today is day ?? still no answer/solution from sophos

     

  • C'mon Sophos. This has to be affecting a lot of customers with large and small networks that use AD SSO, including my own. This should be fixed by now if it's been a known issue for a few days now.

    And while on the topic, it would be great to have a rollback feature when an update is applied instead of having to re-image the UTM.

  • Everyone...

    Sophos admitted it was a bug in 9.501... causes the web filtering proxy to screw up all DNS and web browsing ....

    They dont have a fix or an estimate.. was told to downgrade the firmware in the unit to make it work...

  • I upgraded to 9.414 the other day and experienced all of these issues, then last night I got a notification that a new update was available, 9.501-5.  Like a moron, I decided to try it and now, not only am I experiencing the same SSO issues with Web filtering, but now my remote IPsec VPN users keep getting kicked off.  Is anyone else experiencing IPsec VPN issues (remote access, not site-to-site).  We are using OTP as well as Active Directory for logon.  They can log on, but they keep getting kicked off after a short period of time (2 mins, 20 mins, it's random).