after upgrade to 7.075 proxy with ads sso works so far.
Today i find out, that proxy don't check group membership (my group is http_access from 6.x). Only ADS User+Pass seems to be checked.
So i follow Toms post (http users please read),
and remove astaro-account from ads,
add DNS request route for my-domain.local -> point to DC
and try to (re) join ADC
(fot time issuse , my DC use Astaros NTP-Proxy)
But join fails after a long timeout.
I think the problem is inside dns , because i can't ping myserver.my-domain.local (either thru ssh or support/tools/ping) from asg.
Gregor Kemter