Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

We have an issue where unless we whitelist *.google.com we are unable to login to our Chromebooks using Entra credentials. It will get to the password section then just loop back first saying no network, then returning to the login screen.

 

As whitelisting *.google.com allows it to work it must be a domain that is needed. We have allowed all mentioned by Google Set up a hostname allowlist - Chrome Enterprise and Education Help but still does not work

 

Anyone got an idea what domain is needed?

 

 

Posted

Are you explicit proxy or transparent?

 

Transparent doesn't like you decrypting www.google.com or accounts.google.com and it will just loop round. You don't need to exclude, but you do need to not decrypt when a user is not logged in (and set the client expiration for something like 3-5 mins refreshing every 2)

Posted

That is interesting. We are using transparent and are decrypting both those.

 

I will remove them and see what happens tomorrow

Posted

Obviously you'll want to decrypt www. Because searches, but for the initial login, if you remove that for a test device and log in, you can decrypt again after. 

 

Its finding the way to not decrypt that until you have authenticated. We do it a different way here but its still netsweeper under the hood. 

Posted

Ah interesting you say about decrypting. Both those domains I had as decrypt:// as the URL and Allow.

I have removed the rules, but I'm not sure that is what you are referring to.

Posted

So you weren't secrypting Google searches by default? 

There is a big list of dont decrypt these by Google outside of *.google.com one, ill see if I can find it. 

 

I know www. and accounts. absolutely hate it on transparent mode. 

Posted

There will be shared lists I don't have access to that might be doing it. 

 

When you say do not decrypt it, does it need adding as decrypt://www.google.com (for example) as I always thought that forced it to skip any decryption. If so I will need to add it back in, but then it would need to be removed again once logged in. 
Only way I can think to do that is to have different VLANs, one for device login and then switch to a different one at user level 

Posted (edited)

How I would do it is for my IP policies, so the base level, dont decrypt Google with the decrypt://www.google.com or decrypt://google.com to cover the lot, then the policy that your Chromebooks get authenticated against (via the extension assuming you are using that?) You decrypt www.google.com again, so the exemption is only pre authentication. 

 

If you aren't using the chromebook agent, this would save you for that. I dont want to tread on many toes as this is likely a competitors Netsweeper, but thats how we manage that side of Chromebooks, agent, no syncing of users, just push chromebooks to the policy of choice via the agent config. 

 

This is the list

 

https://support.google.com/chrome/a/answer/6334001?hl=en&ref_topic=3504941#zippy=%2Cenrollment%2Cauto-updates%2Cchromeos-sign-in

 

Googleapis is another domain that we do not decrypt in general, breaks a lot. 

 

Oh and the decrypt://google.com is an Allow entry to stop decryption and Denied to enforce it.

Edited by PaddyNewman

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...