sparkeh Posted April 7, 2017 Posted April 7, 2017 So, to use office 365 we changed our users UPN from domain.local to school.county.sch.uk and our Sophos UTM can't seem to authenticate users against AD with the new UPN (using kerberos) and so AD SSO doesn't work. Users who have their UPN set to domain.local authenticate fine. All our other SSO services work fine. Anyone else seen this? 1
FN-GM Posted April 7, 2017 Posted April 7, 2017 I should imagine you can change the UPN Suffix Sophos looks at? Its not uncommon to use something other than the default UPN suffix.
sparkeh Posted April 7, 2017 Author Posted April 7, 2017 I should imagine you can change the UPN Suffix Sophos looks at? Its not uncommon to use something other than the default UPN suffix. I know right! Its a fairly common thing. Got support looking at it but it doesn't seem straightforward.
Blue_Cookeh Posted April 7, 2017 Posted April 7, 2017 That's an odd one - we don't specify a UPN anywhere in Sophos (I'm guessing it finds the user by LDAP address or username), and in fact I did exactly what you have done regarding Office365 a few years ago now with no ill effect. Definitely one for Sophos support! 1
sparkeh Posted April 7, 2017 Author Posted April 7, 2017 That's an odd one - we don't specify a UPN anywhere in Sophos (I'm guessing it finds the user by LDAP address or username), and in fact I did exactly what you have done regarding Office365 a few years ago now with no ill effect. Definitely one for Sophos support! Thanks. No we don't specify the UPN. Basically, as I understand it, the UTM should just check in with the specified AD server and check username. I've read a few times that Kerberos doesn't even use the UPN in authentication. Its just so weird that users with UPN matching the domain can auth but those not matching can't. And there's literally no info out there on this suggesting its not usually a problem :S
sparkeh Posted April 7, 2017 Author Posted April 7, 2017 @Blue_Cookeh mind if I ask you what you have in your Network -> services -> DNS -> Fowarders and what you have in the Request Routing as well?
sparkeh Posted April 7, 2017 Author Posted April 7, 2017 Ok.... it gets weirder. I can see the kerberos requests hitting the server, and if I run klist on the client I can see a ticket from the UTM's hostname... yet still the winbind errors!
Blue_Cookeh Posted April 8, 2017 Posted April 8, 2017 (edited) @Blue_Cookeh mind if I ask you what you have in your Network -> services -> DNS -> Fowarders and what you have in the Request Routing as well? Our DNS forwarders are set to our two AD DNS servers ('Use forwarders assigned by ISP' is unchecked) and we don't have any forwarders set since we want everything to hit our AD DNS specifically. Have you tried removing the Sophos from your AD and readding it now that you've added the new UPN to AD? Also, it might be worth trying to sync all your AD users/group into Sophos on a schedule. Definitions & Users > Client Authentication > Advanced tab > at the bottom 'Prefetch directory users'. Obviously this is a stab in the dark since neither of us actually know how Sophos works under the hood! Edited April 8, 2017 by Blue_Cookeh 1
sparkeh Posted April 13, 2017 Author Posted April 13, 2017 Ok Sophos suggested renaming the UTM, which we did and now it all works.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now