Jaan Posted February 17, 2017 Posted February 17, 2017 Ok so i've enabled decrypt and scan on our Student WIFI (chromebooks) and have deployed the https cert from the utm (that all works fine). The issue i'm having is that when you start the chromebooks you should get a "enter your email address and password" to sign in screen. Since enabling https scanning i've had exclude "accounts.google.com" from https scanning which gets me a step closer to the Google login page......however.... Once i enter valid account details, i just get a spinning screen....... If i disable https scanning it works fine. (this isn't an option). And i can't exclude the google.com domain from https as we block personal gmail accounts and certain file extensions from google drive. (as well as blocking Google sites but allowing our own official google site page). I've looked on the utm logs for any blocks on web filter\intrusion prevention against the chromebook ip with no luck. Guess i'm asking if anybody knows which urls and domain chromebooks use to login. So i can exclude them from https scanning assuming there's no knock on effect. Googling i have only found "accounts.google.com", but im obviously missing something. At the moment i've made fort out of 80 chromebooks....which is kinda cool.... Thanks in advance for any help or info anybody has.
skell Posted February 17, 2017 Posted February 17, 2017 https://support.google.com/chrome/a/answer/3504942?hl=en Host name whitelist for all Chrome devices accounts.google.com accounts.gstatic.com accounts.youtube.com clients1.google.com clients2.google.com clients3.google.com clients4.google.com commondatastorage.googleapis.com cros-omahaproxy.appspot.com dl.google.com dl-ssl.google.com gweb-gettingstartedguide.appspot.com m.google.com omahaproxy.appspot.com pack.google.com safebrowsing-cache.google.com safebrowsing.google.com ssl.gstatic.com storage.googleapis.com tools.google.com http://www.googleapis.com http://www.gstatic.com Host name whitelist for single-app kiosk devices If you use single-app kiosk devices, whitelist the following host names in addition to the host names listed above: chrome.google.com clients2.googleusercontent.com lh3.ggpht.com lh4.ggpht.com lh5.ggpht.com lh6.ggpht.com mtalk.google.com
Jaan Posted February 17, 2017 Author Posted February 17, 2017 Thanks for the reply, However that would have a huge knock on effect with the reset of the google services we use. its the domain explicitly used for chromeos logins i need. That being said the link you provided is one i didn't find, so i'll have a read of that. cheers
XiJ Posted February 17, 2017 Posted February 17, 2017 Isn't there an option on Sophos UTM to allow certain google domains ? I was looking through some settings on one of our schools today and noticed it. Can't remember the location though !
Jaan Posted February 17, 2017 Author Posted February 17, 2017 Isn't there an option on Sophos UTM to allow certain google domains ? I was looking through some settings on one of our schools today and noticed it. Can't remember the location though ! yes there is, we use this function to allow only school based google accounts. It needs HTTPS decrypt and scan enabled to work.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now