Jump to content

Recommended Posts

Posted
0x9h3 - It was only for testing purposes; we set an exception on Smoothwall to allow the device unfiltered access, with the Sophos web control policy still enabled - when the exception is set or the device is off-network and not going via Smoothwall we don't get the 'ERR_SSL_KEY_USAGE_INCOMPATIBLE' error. Obviously, this isn't a solution, but did allow me to go back to Smoothwall with a bit more.
Posted
I've started seeing stuff relating to v124 however not via HTTPS inspection/proxies, just an older instance.

 

Chrome v124 has re-added the previously experimental quantum jiggery pokery.

 

X25519Kyber768 key encapsulation for TLSProtects current Chrome TLS traffic against future quantum cryptanalysis by deploying the Kyber768 quantum-resistant key agreement algorithm.

 

That is in the release notes and changing this for a machine resolved our issues...

 

A quick fix/test is to add this to registry.

 

Path: SOFTWARE\Policies\Google\Chrome\PostQuantumKeyAgreementEnabled Type: DWORD Value: 0
Path: SOFTWARE\Policies\Microsoft\Edge\PostQuantumKeyAgreementEnabled Type: DWORD Value: 0

 

See if that helps your browsing I guess...

 

 

Hi all,

We are also having problems with this.... We have applied this registry key and rebooted and it seems to be working... have tested it on a few pcs so far before rolling it out..

 

have tested it in Edge as well and it's also working. Brill :)

 

We have disabled Chrome updating itself so will roll this key out and then remove that gpo setting, and see what happens.

 

We use Lightspeed and Sophos..

 

Thankyou Paddy!

 

Much appreciated,

Gary,

  • Thanks 1
Posted

Hi both,

 

The registry key fix appears to be intermittent for us. Some computer it works and others it does nothing.

 

Have you heard back from Sophos? I find their support terrible to say the least...

Posted

Is it the reg fix from g_sturges that your are finding to be intermittent.

 

Sophos' response was essentially turn off web control and we won't see the warning (very helpful). I've gone back to Smoothie, as when we set an exception for the device or worked off-net it was fine.

Posted

The registry is a direct attack, there are various other "sane" options utilising the Chrome/Edge ADMX provisions in group policy.

 

Same item, just pushed out to all machines rather than registry. Might give you more success if you hammer the browser shut directly as its going to force the flag (chrome://flags - search "kyber") to be disabled.

Posted

Hi all,

 

I have turned off the web control feautures of Sophos and deployed the reg keys and its still the same. On site, if I remove Sophos I still have the same issue. The only way I have found to resolve the issue is to add the IP address of the computer into Smoothwall exceptions (which obviously I do not want to do). Staff taking laptops home the browsers work fine.

 

I have a ticket still open with SMoothwall just been escalated to 2nd line.

Posted
The root cause (a fun incompatibility between the cert we generate, and what Sophos likes) has been identified, and a fix is in the works. Matt, we should be able to hotfix your system this week
  • Thanks 1
Posted
I'm with Netsweeper, so whilst you can't comment on exact fixes obviously, but is this likely to mean a new cert or is the fixes more backend?
Posted
We've seen this issue but only for a number of users. We use Smoothwall and Sophos and it seems to only affect Edge & Chrome, Firefox looks unaffected.
Posted
Drop me an email with a ticket number. The fix is in Leeds-75 (but it is already hotfixable). L75 is currently in internal staff testing, first customer release next week.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...