Quantcast
Channel: Sophos User Bulletin Board
Viewing all articles
Browse latest Browse all 14361

Feature Retired: Multiple AD Domain Support

$
0
0
Ladies and Gents,

We have just found out the hard way - support for multiple AD Domain controller SSO has been dropped by Astaro after 8.103. It is a low priority for Astaro to re-instate because they only know of two customers so far affected by this. We have one customer (and a second who will be affected when they upgrade past 8.103).

Are any of you, or your customers also likely to be affected by this change???????

The issue is that Astaro can no longer distinguish groups of the same name (like Active Directory Users) on different DCs. This means that if you add the group from one DC, you effectively add all the groups of the same name from all the DCs. Not a problem if that is the required behaviour. The work around is to make sure that all the groups added to Astaro, across all the domain controllers have unique names on the DCs.

This workaround is only practical if you have full control and full access over all DCs. However when you have different IT Directors/IT Teams per DC then this becomes very painful.

So if you have, or are a customer on 8.103 or earlier with multiple AD controllers working with SSO, you might wish to take advice before going to 8.2xx or later.

Best Regards,

Adrien

Viewing all articles
Browse latest Browse all 14361

Trending Articles