richmackie Posted October 2, 2019 Posted October 2, 2019 I haven't seen this topic anywhere else but if someone's already posted the same question I apologise. I look after a primary school who, after many years, decided to ditch their ICT suite full of 8 year old Windows 7 PCs and buy a load of Chromebooks. We had a look at Wonde SSO and we made a joint decision to implement it so that young kids don't have to remember usernames and passwords, and one login will not only get them into the Chromebook and G Suite, but also other web-based products they use. When we came to set up SSO, the Wonde logon doesn't work when connected to the school network; as soon as I try to log on it comes up with a network error as if it isn't connected to anything. It does work when tethered to a phone. The school have Updata broadband which comes with Netsweeper filtering. All devices have to have an SSL certificate installed for inspection - which I think must be pretty standard in schools these days. Not sure about any other broadband providers but I know RM works in a similar way. Looking at the logs in Netsweeper, the device is trying to talk to google.com on port 443 and throwing an encryption error. Usually when that happens we have the website in question added to a do not decrypt list but we wouldn't want to do that for Google. Anyway, doing some digging I find that if I log into the Chromebook another way, then go to edu.wonde.com, I can sign in without issue. Also, if I use guest mode on a Chromebook the SSL certificate isn't available and I have to install it if I want to use any SSL websites. All of which makes me think that the Chromebooks aren't using the SSL certificate during the login process. My theory is that I need to specify this in the admin console under Single Sign-on client certificates and so far I just haven't got the right syntax. I'm hoping, based on the popularity of Wonde, Updata and Netsweeper (so they claim anyway) that someone else has had the same problem and fixed it. If anyone can help, thanks in advance.
DGardiner Posted October 2, 2019 Posted October 2, 2019 I haven't seen this topic anywhere else but if someone's already posted the same question I apologise. I look after a primary school who, after many years, decided to ditch their ICT suite full of 8 year old Windows 7 PCs and buy a load of Chromebooks. We had a look at Wonde SSO and we made a joint decision to implement it so that young kids don't have to remember usernames and passwords, and one login will not only get them into the Chromebook and G Suite, but also other web-based products they use. When we came to set up SSO, the Wonde logon doesn't work when connected to the school network; as soon as I try to log on it comes up with a network error as if it isn't connected to anything. It does work when tethered to a phone. The school have Updata broadband which comes with Netsweeper filtering. All devices have to have an SSL certificate installed for inspection - which I think must be pretty standard in schools these days. Not sure about any other broadband providers but I know RM works in a similar way. Looking at the logs in Netsweeper, the device is trying to talk to google.com on port 443 and throwing an encryption error. Usually when that happens we have the website in question added to a do not decrypt list but we wouldn't want to do that for Google. Anyway, doing some digging I find that if I log into the Chromebook another way, then go to edu.wonde.com, I can sign in without issue. Also, if I use guest mode on a Chromebook the SSL certificate isn't available and I have to install it if I want to use any SSL websites. All of which makes me think that the Chromebooks aren't using the SSL certificate during the login process. My theory is that I need to specify this in the admin console under Single Sign-on client certificates and so far I just haven't got the right syntax. I'm hoping, based on the popularity of Wonde, Updata and Netsweeper (so they claim anyway) that someone else has had the same problem and fixed it. If anyone can help, thanks in advance. you need to not inspect or authenticate the accounts.google.com and accounts.youtube.com urls - theres a long list of stuff i had to add to our smoothwall. id assume the wonde sso page may also need some exceptions 1
richmackie Posted October 2, 2019 Author Posted October 2, 2019 There were some other URLs we had to add to the do not decrypt list - which I think is the same as do not inspect - but because it's one list for a large number of schools I'm not sure adding anything to do with Google will be allowed. Wonde don't seem to document this which seems odd.
DGardiner Posted October 2, 2019 Posted October 2, 2019 There were some other URLs we had to add to the do not decrypt list - which I think is the same as do not inspect - but because it's one list for a large number of schools I'm not sure adding anything to do with Google will be allowed. Wonde don't seem to document this which seems odd. Heres the official google list: https://support.google.com/chrome/a/answer/6334001 i just picked and choose until our chromebooks logged in propperly trying to avoid anything i thought might muck up google.com filtering 1
richmackie Posted October 3, 2019 Author Posted October 3, 2019 Well the plot thickens...I've done some testing with my network expert and we've narrowed the issue down to inspecting traffic to Google. Any other URLs the device needs to talk to have been added to the bypass list and the logs show it's talking to those without issue, but as soon as I try to log in it throws errors with Google. If we allow the device to talk to whatever it likes without inspection, it logs straight in. Now, surely all schools have SSL inspection these days? And traffic to google.com has to be inspected otherwise you'd have kids searching for all sorts. So if any schools are using Wonde SSO on Chromebooks, and there must be some, how did they get past this issue?
ModeratelyGruntled Posted February 14, 2020 Posted February 14, 2020 Hi I have a very similar issue but I'm using login.microsoftonline as the third-party IdP in Chrome Management, so everyone can sign into Chrome devices/GSuite using their Office 365 credentials. We have Smoothwall provided by our LA but have no administrative control over it, and our current workaround involves authenticating and completing the log-in process on a 'public' SSID (on which I can assume no or very limited SSL inspection takes place) before the user can manually join the curriculum SSID. Given that this configuration is supported by google, and as you say fairly commonplace, shouldn't Smoothwall/Netsweeper support this somehow? I don't have a support account with Smoothwall so cannot verify!
5tu Posted February 14, 2020 Posted February 14, 2020 I have the same problem. We use Azure AD as our identity provider for GSuite SSO but Chromebook login only works if I add "google.com" to the Do Not Inspect policy in Smoothwall which I obviously can't do for Safeguarding reasons. I have a support case open with Smoothwall (ongoing since november) but still no further forward. Latest suggestion is to use the new Smoothwall Cloud Filter for Chromebooks which they say will work around the issue. I'm currently waiting for this to be implemented...... 1
richmackie Posted February 14, 2020 Author Posted February 14, 2020 An update for anyone who's interested - apparently it's to do with the level of inspection - we have a "deep" inspection in Netsweeper which is causing the issue. I'm told that can be reconfigured and it's being worked on as it's causing other issues with other schools, but no joy so far. gybe78 - I may be wrong about this but I think other schools have solved this with Smoothwall. Wonde tech support gave me some information which might be of use - PM me if you like - but I'm sure it's the level of inspection that's the issue. My problem is I'm not in control of Netsweeper so I can't see how it's set up or make changes. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now