Jump to content

Recommended Posts

Posted

Ok so i've enabled decrypt and scan on our Student WIFI (chromebooks) and have deployed the https cert from the utm (that all works fine).

 

The issue i'm having is that when you start the chromebooks you should get a "enter your email address and password" to sign in screen.

 

Since enabling https scanning i've had exclude "accounts.google.com" from https scanning which gets me a step closer to the Google login page......however....

 

Once i enter valid account details, i just get a spinning screen.......

 

If i disable https scanning it works fine. (this isn't an option). And i can't exclude the google.com domain from https as we block personal gmail accounts and certain file extensions from google drive. (as well as blocking Google sites but allowing our own official google site page).

 

I've looked on the utm logs for any blocks on web filter\intrusion prevention against the chromebook ip with no luck.

 

Guess i'm asking if anybody knows which urls and domain chromebooks use to login. So i can exclude them from https scanning assuming there's no knock on effect.

 

Googling i have only found "accounts.google.com", but im obviously missing something.

 

At the moment i've made fort out of 80 chromebooks....which is kinda cool....

 

Thanks in advance for any help or info anybody has.

Posted

https://support.google.com/chrome/a/answer/3504942?hl=en

 

Host name whitelist for all Chrome devices

accounts.google.com

accounts.gstatic.com

accounts.youtube.com

clients1.google.com

clients2.google.com

clients3.google.com

clients4.google.com

commondatastorage.googleapis.com

cros-omahaproxy.appspot.com

dl.google.com

dl-ssl.google.com

gweb-gettingstartedguide.appspot.com

m.google.com

omahaproxy.appspot.com

pack.google.com

safebrowsing-cache.google.com

safebrowsing.google.com

ssl.gstatic.com

storage.googleapis.com

tools.google.com

http://www.googleapis.com

http://www.gstatic.com

 

Host name whitelist for single-app kiosk devices

If you use single-app kiosk devices, whitelist the following host names in addition to the host names listed above:

 

chrome.google.com

clients2.googleusercontent.com

lh3.ggpht.com

lh4.ggpht.com

lh5.ggpht.com

lh6.ggpht.com

mtalk.google.com

Posted

Thanks for the reply,

 

However that would have a huge knock on effect with the reset of the google services we use. its the domain explicitly used for chromeos logins i need.

 

That being said the link you provided is one i didn't find, so i'll have a read of that.

 

cheers

Posted
Isn't there an option on Sophos UTM to allow certain google domains ? I was looking through some settings on one of our schools today and noticed it. Can't remember the location though !
Posted
Isn't there an option on Sophos UTM to allow certain google domains ? I was looking through some settings on one of our schools today and noticed it. Can't remember the location though !

 

yes there is, we use this function to allow only school based google accounts. It needs HTTPS decrypt and scan enabled to work.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...