0x9h3 Posted April 23, 2024 Posted April 23, 2024 Hi mattjones, What exceptions on Smoothwall box did you make please
mattjones Posted April 23, 2024 Posted April 23, 2024 0x9h3 - It was only for testing purposes; we set an exception on Smoothwall to allow the device unfiltered access, with the Sophos web control policy still enabled - when the exception is set or the device is off-network and not going via Smoothwall we don't get the 'ERR_SSL_KEY_USAGE_INCOMPATIBLE' error. Obviously, this isn't a solution, but did allow me to go back to Smoothwall with a bit more.
g_sturges Posted April 23, 2024 Posted April 23, 2024 I've started seeing stuff relating to v124 however not via HTTPS inspection/proxies, just an older instance. Chrome v124 has re-added the previously experimental quantum jiggery pokery. X25519Kyber768 key encapsulation for TLSProtects current Chrome TLS traffic against future quantum cryptanalysis by deploying the Kyber768 quantum-resistant key agreement algorithm. That is in the release notes and changing this for a machine resolved our issues... A quick fix/test is to add this to registry. Path: SOFTWARE\Policies\Google\Chrome\PostQuantumKeyAgreementEnabled Type: DWORD Value: 0 Path: SOFTWARE\Policies\Microsoft\Edge\PostQuantumKeyAgreementEnabled Type: DWORD Value: 0 See if that helps your browsing I guess... Hi all, We are also having problems with this.... We have applied this registry key and rebooted and it seems to be working... have tested it on a few pcs so far before rolling it out.. have tested it in Edge as well and it's also working. Brill We have disabled Chrome updating itself so will roll this key out and then remove that gpo setting, and see what happens. We use Lightspeed and Sophos.. Thankyou Paddy! Much appreciated, Gary, 1
0x9h3 Posted April 23, 2024 Posted April 23, 2024 Hi both, The registry key fix appears to be intermittent for us. Some computer it works and others it does nothing. Have you heard back from Sophos? I find their support terrible to say the least...
mattjones Posted April 23, 2024 Posted April 23, 2024 Is it the reg fix from g_sturges that your are finding to be intermittent. Sophos' response was essentially turn off web control and we won't see the warning (very helpful). I've gone back to Smoothie, as when we set an exception for the device or worked off-net it was fine.
PaddyNewman Posted April 23, 2024 Posted April 23, 2024 The registry is a direct attack, there are various other "sane" options utilising the Chrome/Edge ADMX provisions in group policy. Same item, just pushed out to all machines rather than registry. Might give you more success if you hammer the browser shut directly as its going to force the flag (chrome://flags - search "kyber") to be disabled.
0x9h3 Posted April 24, 2024 Posted April 24, 2024 Hi all, I have turned off the web control feautures of Sophos and deployed the reg keys and its still the same. On site, if I remove Sophos I still have the same issue. The only way I have found to resolve the issue is to add the IP address of the computer into Smoothwall exceptions (which obviously I do not want to do). Staff taking laptops home the browsers work fine. I have a ticket still open with SMoothwall just been escalated to 2nd line.
tom_newton Posted April 24, 2024 Posted April 24, 2024 We are investigating wether something we present as a cert is triggering a little bugette in Sophos. More info when we get it. 3
tom_newton Posted April 29, 2024 Posted April 29, 2024 Our first supposition for what is triggering the bug (key length) made no difference. Drawing board will be returned to.
tom_newton Posted April 30, 2024 Posted April 30, 2024 The root cause (a fun incompatibility between the cert we generate, and what Sophos likes) has been identified, and a fix is in the works. Matt, we should be able to hotfix your system this week 1
Patrick Posted May 1, 2024 Posted May 1, 2024 I'm with Netsweeper, so whilst you can't comment on exact fixes obviously, but is this likely to mean a new cert or is the fixes more backend?
tom_newton Posted May 1, 2024 Posted May 1, 2024 The fix is in how we generate the individual mitm certs per-site but not a change to the CA, so it should be super easy to roll out a fix
jcs808 Posted May 2, 2024 Posted May 2, 2024 We've seen this issue but only for a number of users. We use Smoothwall and Sophos and it seems to only affect Edge & Chrome, Firefox looks unaffected.
tom_newton Posted May 9, 2024 Posted May 9, 2024 Drop me an email with a ticket number. The fix is in Leeds-75 (but it is already hotfixable). L75 is currently in internal staff testing, first customer release next week. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now