Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Web Security: HTTP/HTTPS/FTP, IM/P2P, Web Filtering and Antivirus

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-04-2010, 04:31 PM
Junior Member
 
Join Date: Jan 2010
Location: Oberhausen
Posts: 15
Default eDirectory Authentication with SSO lost over the day

Hello,

here i have a new problem for you.

In the morning i login to my computer with my NOVELL client switched on the SSO and i work a short time in the local network an internet and all is working fine.

Than i leave my computer alone for some hours. No screen saver, no sleeping mode or somthing like this.

So after some houres i come back working. My computer is in the same situation as i have left.

I work with the local network that is ok.

Than i try to brows to the internet and i am not authenticated.

The Authentication POP up is rising und i have to give my username and password. Than only _THIS_ session is authenticated. When i close the browse and open it again, it is the same way as before.

Has someone an idea how to solve this kind of problem?
__________________
Kind Regrads
Jens Geier

-------------------------------------------------
ASTARO - ASG425
FW : 7.500
-------------------------------------------------
b+w electronic systems
http://www.b-w.com
-------------------------------------------------
Reply With Quote
  #2 (permalink)  
Old 02-04-2010, 05:14 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,393
Default

Jens, please state your browser name and version. Also, version of Astaro.

I think the only browser certified to work with Astaro SSO is Internet Explorer (IE7 and I think with V7.50x, IE8); there are known issues with Chrome and Firefox.

Cheers- Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #3 (permalink)  
Old 02-04-2010, 05:45 PM
Junior Member
 
Join Date: Jan 2010
Location: Oberhausen
Posts: 15
Default

Quote:
Originally Posted by BAlfson View Post
Jens, please state your browser name and version. Also, version of Astaro.

I think the only browser certified to work with Astaro SSO is Internet Explorer (IE7 and I think with V7.50x, IE8); there are known issues with Chrome and Firefox.

Cheers- Bob
Hello Bob,

i use Firexof Version 3.6 and ASTARO ASG-425 V7.500.

If there are some known issues with Firefox, i will try this with IE8 Tomorrow again.

IE 8.0.6001.18702
__________________
Kind Regrads
Jens Geier

-------------------------------------------------
ASTARO - ASG425
FW : 7.500
-------------------------------------------------
b+w electronic systems
http://www.b-w.com
-------------------------------------------------
Reply With Quote
  #4 (permalink)  
Old 02-09-2010, 11:16 AM
Junior Member
 
Join Date: Jan 2010
Location: Oberhausen
Posts: 15
Default

Quote:
Originally Posted by jgeier View Post
Hello Bob,

i use Firexof Version 3.6 and ASTARO ASG-425 V7.500.

If there are some known issues with Firefox, i will try this with IE8 Tomorrow again.

IE 8.0.6001.18702
Hello,

it doesen't matter i use IE8 or Firefox.

Over the day _BOTH_ lost the authentication !!!!
__________________
Kind Regrads
Jens Geier

-------------------------------------------------
ASTARO - ASG425
FW : 7.500
-------------------------------------------------
b+w electronic systems
http://www.b-w.com
-------------------------------------------------
Reply With Quote
  #5 (permalink)  
Old 02-09-2010, 02:10 PM
Member
 
Join Date: Oct 2008
Posts: 62
Default

You're not alone I have the same sort of issues all over my campus with 7.502 and edirectory-SSO.

My users have just gotten used to it (although they still complain occasionally). We just tell them to reboot (they love that )

And I've given up on trying to isolate it because it just seems so random....
__________________
ASG v7.502 Software -- HP360G5, Quad Xeon E5410, 4GB RAM -- 500 User
Reply With Quote
  #6 (permalink)  
Old 02-09-2010, 07:26 PM
SveN's Avatar
Senior Member
 
Join Date: Nov 2000
Location: Frankfurt, Germany
Posts: 374
Default

anything in the aua.log?
Reply With Quote
  #7 (permalink)  
Old 02-10-2010, 03:24 PM
addrockk's Avatar
Member
 
Join Date: Jan 2008
Posts: 45
Default

Quote:
Originally Posted by jgeier View Post
Hello,

here i have a new problem for you.

In the morning i login to my computer with my NOVELL client switched on the SSO and i work a short time in the local network an internet and all is working fine.

Than i leave my computer alone for some hours. No screen saver, no sleeping mode or somthing like this.

So after some houres i come back working. My computer is in the same situation as i have left.

I work with the local network that is ok.

Than i try to brows to the internet and i am not authenticated.

The Authentication POP up is rising und i have to give my username and password. Than only _THIS_ session is authenticated. When i close the browse and open it again, it is the same way as before.

Has someone an idea how to solve this kind of problem?
This seems like an eDirectory issue. The eDir SSO looks at the IP you're connecting to the proxy from and searches eDir for an object with that IP in the Network Address field. If you lose SSO with Astaro, check that field on your user object in eDir and see if its still populated. If it isn't, you're eDir server doesn't think you're logged in anymore.
Reply With Quote
  #8 (permalink)  
Old 02-15-2010, 12:43 PM
Junior Member
 
Join Date: Jan 2010
Location: Oberhausen
Posts: 15
Default

Quote:
Originally Posted by SveN View Post
anything in the aua.log?
Hello Sven,

what is the aua.log?

where i can find it?
__________________
Kind Regrads
Jens Geier

-------------------------------------------------
ASTARO - ASG425
FW : 7.500
-------------------------------------------------
b+w electronic systems
http://www.b-w.com
-------------------------------------------------
Reply With Quote
  #9 (permalink)  
Old 02-15-2010, 12:49 PM
Junior Member
 
Join Date: Jan 2010
Location: Oberhausen
Posts: 15
Default

Quote:
Originally Posted by addrockk View Post
This seems like an eDirectory issue. The eDir SSO looks at the IP you're connecting to the proxy from and searches eDir for an object with that IP in the Network Address field. If you lose SSO with Astaro, check that field on your user object in eDir and see if its still populated. If it isn't, you're eDir server doesn't think you're logged in anymore.
Hello Addrockk,

do you know the exact field that is tested in the user object?

In ConsoleOne of an user Object i find in the tab General the menue Environment.

Here there should be the Network address.

But usualy this field is empty.
__________________
Kind Regrads
Jens Geier

-------------------------------------------------
ASTARO - ASG425
FW : 7.500
-------------------------------------------------
b+w electronic systems
http://www.b-w.com
-------------------------------------------------
Reply With Quote
  #10 (permalink)  
Old 02-15-2010, 03:15 PM
Junior Member
 
Join Date: Jan 2010
Location: Oberhausen
Posts: 15
Default

I have an idea why this could may be happend.
I hope some one can agree to this.

In our company we have several NetWare Servers in some diffrent states.

there are
- 2 x NW6.5 SP7
- 1 x NW6.5 SP6
- 2 x OES 2 SP 2a

some times the sync between is not so good so we use DSREPAIR on all of the NW6.5 servers.

And it looks that after using DSREPAIR the entry of the IP Adress in the User Object is gon.

Also i find somthing interesting here. I use two computers to login to the Network with the same username.

So i find ofcause two diffrerent IP-Adresses in the user object but the writing is interesting.

For the first computer i found

IP: 10.0.90.46

and for the second i found

TCP: 10.0.90.50

Ofcause the adress should be different but not the protocol ....

Has some one an idea for this?
__________________
Kind Regrads
Jens Geier

-------------------------------------------------
ASTARO - ASG425
FW : 7.500
-------------------------------------------------
b+w electronic systems
http://www.b-w.com
-------------------------------------------------
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 06:54 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.