Jump to content

Recommended Posts

Posted

So, to use office 365 we changed our users UPN from domain.local to school.county.sch.uk and our Sophos UTM can't seem to authenticate users against AD with the new UPN (using kerberos) and so AD SSO doesn't work.

 

Users who have their UPN set to domain.local authenticate fine.

 

All our other SSO services work fine.

 

Anyone else seen this?

  • Thanks 1
Posted
I should imagine you can change the UPN Suffix Sophos looks at? Its not uncommon to use something other than the default UPN suffix.
Posted
I should imagine you can change the UPN Suffix Sophos looks at? Its not uncommon to use something other than the default UPN suffix.

I know right! Its a fairly common thing. Got support looking at it but it doesn't seem straightforward.

Posted
That's an odd one - we don't specify a UPN anywhere in Sophos (I'm guessing it finds the user by LDAP address or username), and in fact I did exactly what you have done regarding Office365 a few years ago now with no ill effect. Definitely one for Sophos support!
  • Thanks 1
Posted
That's an odd one - we don't specify a UPN anywhere in Sophos (I'm guessing it finds the user by LDAP address or username), and in fact I did exactly what you have done regarding Office365 a few years ago now with no ill effect. Definitely one for Sophos support!

Thanks.

 

No we don't specify the UPN. Basically, as I understand it, the UTM should just check in with the specified AD server and check username. I've read a few times that Kerberos doesn't even use the UPN in authentication. Its just so weird that users with UPN matching the domain can auth but those not matching can't. And there's literally no info out there on this suggesting its not usually a problem :S

Posted

Ok.... it gets weirder.

 

I can see the kerberos requests hitting the server, and if I run klist on the client I can see a ticket from the UTM's hostname... yet still the winbind errors!

Posted (edited)
@Blue_Cookeh mind if I ask you what you have in your Network -> services -> DNS -> Fowarders and what you have in the Request Routing as well?

 

Our DNS forwarders are set to our two AD DNS servers ('Use forwarders assigned by ISP' is unchecked) and we don't have any forwarders set since we want everything to hit our AD DNS specifically.

 

Have you tried removing the Sophos from your AD and readding it now that you've added the new UPN to AD? Also, it might be worth trying to sync all your AD users/group into Sophos on a schedule. Definitions & Users > Client Authentication > Advanced tab > at the bottom 'Prefetch directory users'.

 

Obviously this is a stab in the dark since neither of us actually know how Sophos works under the hood!

Edited by Blue_Cookeh
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...