I have a few questions around how the UTM authenticates Mac OSX clients. Any official Sophos answers on these please?
1. Is Mac OSX Single Sign On (against AD) possible in Sophos UTM 9.2? similar to the Sophos Web Appliance.
The SWA had the caveat that the Service Principle Name must be set in Active Directory to facilitate Single Sign on for Mac OSX devices (as in help here: Configuring Active Directory to support Kerberos for Mac OS X) Ensuring Kerberos is used for authentication etc.
Is this the same to support Sophos UTM SSO for Mac devices? It is not mentioned in the Help for UTM yet (I am running early release of UTM 9.2)
2. Is the newer Transparent Single Sign On supported for Mac OSX?
Doesn't mention anything specific other than It is only supported for Internet Explorer. Is it supported for Mac browsers also if the browser is capable? I think there are some changes required for Firefox to support auto Kerberos Authentication (add SWA URI to network.negotiate-auth.trusted-uris property etc). It is available to pick for a device specific policy.
3. Using browser authentication. Can you specify the time of the session? what is the default time or how does the UTM determine the session time? (ie when will the users have to authenticate again?)
The SWA included an option when using browser authentication or Captive Portal to adjust the time for the session. Is there a default time for the UTM? (1 hour similar to SWA?). This is not mentioned in the Help file. Can the time be adjusted?
4. Support for Apple OpenDirectory.
It is still mentioned in the Help file that Apple OpenDirectory SSO (including uploading kerberos ticket etc) is supported for Web Protection Authentication. Is this correct? I remember hearing that support for this was being dropped. Please confirm. Open directory is not an available option in adding an authentication server from what I can see.