Jump to content

Recommended Posts

Posted

A teacher wants to do a "AQA new specification live online event", he's been sent an email with instructions.

 

We've had to install the Adobe Connect plugin - but it still only works for domain admins and not teachers.

 

He gets a certificate warning and no matter what he chooses he cannot proceed...

 

Screenshot attached.

 

Anyone know why?

 

I presume it's a Group Policy setting that's allowing it to work for domain admins - but if anyone can shed any light on which one before I spend my day with some trial and error....

 

Cheerscert.jpg

Posted
Have you checked you AV, and logs?

 

Not sure that's relevant....

 

If I log in as a domain admin it works....

 

It must be either security restrictions (GPO's) or filtering related....

Posted
But your fault is with a user (Teacher) who is not i hope a domain admin. Yes possible a gpo/web filter can you filter/track the site route via your firewall under that user to see if it is blocked?
Posted
The AV is relevant if it is blocking any required plugins that are needed or stopping the cert in the browser. If it is a gpo the check the event logs you could also push out the required cert via a gpo.
Posted
But your fault is with a user (Teacher) who is not i hope a domain admin. Yes possible a gpo/web filter can you filter/track the site route via your firewall under that user to see if it is blocked?

 

 

If I take a test teacher account and leave it in place in active directory but edit the users groups so it becomes members of domain admins, administrators etc - then it works....

 

Smoothwall uses the admin group to determine which level of filtering to provide.

 

If I move the user to the OU where the network admins are but leave the group membership alone then it does n't work....

Posted
So your test user get out via a proxy filter or just via firewall? ie are all normal user block/allow via the proxy or is it via the firewall groups. We did have a similar issue were the connection tried to bypass the proxy for users and go straight to the firewall/gateway just checking our old jobs soloutions.
Posted
I encountered a similar issue previously, the solution was to not use the Connect plugin and just try to connect to the meeting (or a test meeting I think they have available), it defaults to some other "player" and I never had any problems with it. I'm not sure why it worked that way for teachers but I'd guess that it's related to the filtering system and how Connect interacts with it (or doesn't).
Posted
So just checking via our firewall and under our test teacher it is trying to bypass the users proxy settings which will then stop it from being used. We had to add a rule in the firewall to allow this
Posted
So just checking via our firewall and under our test teacher it is trying to bypass the users proxy settings which will then stop it from being used. We had to add a rule in the firewall to allow this

 

sadly we don't manager our own firewall - good old SWGfL

 

do you have the details of what I'd have to ask them to open? Many thanks.

Posted
I encountered a similar issue previously, the solution was to not use the Connect plugin and just try to connect to the meeting (or a test meeting I think they have available), it defaults to some other "player" and I never had any problems with it. I'm not sure why it worked that way for teachers but I'd guess that it's related to the filtering system and how Connect interacts with it (or doesn't).

 

If I try to connect to the meeting as the user - and not run the test - I repeatedly get the YES/NO/View Cert dialogue box appear - pressing YES repeatedly does not seem to do anything :(

 

- - - Updated - - -

 

So your test user get out via a proxy filter or just via firewall? ie are all normal user block/allow via the proxy or is it via the firewall groups. We did have a similar issue were the connection tried to bypass the proxy for users and go straight to the firewall/gateway just checking our old jobs soloutions.

 

All users go out via the same proxy - the smoothwall box....I cannot bypass this....

Posted
Hi again sorry it has drag on a bit, So via our firewall monitoring adobe connect does try to bypass the proxy, you would need to contact you firewall peeps and get them to monitor the traffic will you attempt to connect. They should then do all the tweaking for you and give you details of what they did for your records. Also when the plugin tried to install the AV did grab it but a quick exclusion sorted that. Hope that helps a bit.
Posted
Disable the 'check for certificate revocation' options in Internet Explorer?

 

A group policy denies access to Internet Tools for staff :( - stops them messing about with stuff....

 

Is there a group policy to disable the check?

Posted

I found the policy :

 

User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/advanced Page/Check for Server certificate revocation.

 

and changed it....

 

I no longer get the YES/NO/View certificate pop-up - it just fails to connect....

 

cert2.jpg

Posted

 

 

[ATTACH=CONFIG]31050[/ATTACH]

 

Have you seen the details button, are you able to access the site its listed it as teacher?

Posted
Hi, Ive just had to set this up through smoothwall. Probably not very secure but after disabling server certificate revocation checking I then allowed all port access to 66.235.128.0/19 in networking>outgoing>policys to allow it to connect (the ip range belongs to adobe).
Posted
Hi, Ive just had to set this up through smoothwall. Probably not very secure but after disabling server certificate revocation checking I then allowed all port access to 66.235.128.0/19 in networking>outgoing>policys to allow it to connect (the ip range belongs to adobe).

 

I don't have a networking->outgoing-> option :(

Posted

Smoothwall took a look and did the following:

 

Added aqa.adobeconnect.com to Guardian » Policy objects » Categories and then also clicked on advanced and added .adobeconnect.com to URL patterns.

 

The teacher is doing the call at 4pm today - so fingers crossed.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...