Jump to content

mattjones

Members
  • Posts

    48
  • Joined

  • Last visited

Reputation

10 Good

About mattjones

  1. Is it the reg fix from g_sturges that your are finding to be intermittent. Sophos' response was essentially turn off web control and we won't see the warning (very helpful). I've gone back to Smoothie, as when we set an exception for the device or worked off-net it was fine.
  2. 0x9h3 - It was only for testing purposes; we set an exception on Smoothwall to allow the device unfiltered access, with the Sophos web control policy still enabled - when the exception is set or the device is off-network and not going via Smoothwall we don't get the 'ERR_SSL_KEY_USAGE_INCOMPATIBLE' error. Obviously, this isn't a solution, but did allow me to go back to Smoothwall with a bit more.
  3. BOOT3988 - what is your environment? Smoothwall? Sophos? I've gone back to Smoothwall on this, as when we tested off-network with Sophos enabled it worked fine and when we set an exception for a device on the smoothwall appliance (keeping sophos web control enabled) we didn't receive the ssl errors.
  4. @BOOT3988, it is not, hence for testing purposes only.
  5. Yes, exactly the same issue as Edge, as it is built on Chromium. The Sophos options above resolves the problem in Edge too.
  6. I have only temporarily disabled the policy on a client for testing. Sophos client > admin sign-in > enter tamper protection password and then override policies and turn off realtime scanning for internet and then 'web control' under 'controls on users'. For clients that have updated to v124 we have rolled them back to a previous version: taskkill /F /IM chrome.exe /T msiexec /i "googlechromestandaloneenterprise64.msi" /quiet (version 124 MSI) timeout /t 120 msiexec /x "googlechromestandaloneenterprise64.msi" /quiet (version 124 MSI) timeout /t 20 msiexec /i "googlechromestandaloneenterprise64-v123.msi" /quiet (version 123 MSI - or whatever you have available) Set the reg key: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Update\UpdateDefault to 0 The client will then be on an earlier version and can't update. Ive opened a case with Sophos for their thoughts.
  7. We have just tested this by temporarily disabling real time scanning for 'internet' and web control under Controls on Users. Close and lose the load browser. For the time being we have disabled Chrome updates and rolled users back to a previous version. I've just opened a ticket with Sophos to investigate further so will keep you posted.
  8. It looks like the issue actually lies with Sophos - do you have web control enabled or a different endpoint security product?
  9. Our CA was renewed in Feb 24 and has an expiry date of Feb 26, so unfortunately this doesn't appear to be the issue in our case. As mentioned above and in a post on a Google community thread: https://support.google.com/chrome/a/thread/269732161/version-124-0-6367-61-back-to-giving-err-ssl-key-usage-incompatible-and-prior-workaround-not-working?msgid=270044340#, the key usage appears to be set correctly on the Smoothwall generated cert - it shows Digital Signature.
  10. We are experiencing this too - @tom_newton is looking into this for us. The certificate is showing signing under keyusage. The now deprecated rsaKeyUsageForLocalAnchorsEnabled was working fine up until v124. We first saw this back in November 23. We have rolled users back to a previous version as a temporary fix until we've had an update from Smoothie.
  11. Hi, I am interested to know how schools/trusts store their network documentation. Is anyone using IT Glue or similar? Thanks, Matt
  12. Sorry to bring up a really old post, but did you go with ITGlue or something else? Thanks, Matt - - - Updated - - - Sorry to bring up a really old post, but did you go with ITGlue or something else? Thanks, Matt
  13. That's really interesting, thank you ever so much for sharing this info. A few questions, if I may. I too, have pondered as of late about the efficiency of 'day or half a day a week' support sessions - are you simply providing ad-hoc support in its place? In regards to your WAN infrastructure - do you have a single or multiple internet breakout points? Which service provider have you gone with for this solution? Thanks.
  14. Hi, Has anyone been involved in the merging of 2 (or more) MATs/MACs? If so: What was/is your experience? Were you the technical lead? What did you set out to achieve as part of the merge from a technical angle? (single AD?, forest level trusts?, How did you support structure change? Thanks in advance to those willing to comment - feel free to DM me if your experience wasn't great, but don't wish for it to be public Matt
×
×
  • Create New...