ProxySG & Advanced Secure Gateway

 View Only
  • 1.  Unable to authenticate to InTune Company Portal

    Posted Nov 16, 2018 01:41 PM

    Hello all, 

    One of our system administrators is having issues with registering apple devices (macs) to Microsoft's InTune Compay Portal. The issue is when attempting to log into the Company Portal. The users attempt to log in and receives  "Company Portal Temporarily Unavailable - The Company portal encountered a problem.". I have done all I can, I even proxy bypassed the users IP address and it worked. 

    Now, I am looking for a better option that using static bypass because we're talking about 100's of devices here. I am not that savy around Blue Coats so a large portion of this is new to me.  I have included some logs which may help....

     

    2018-11-16 13:02:36-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:37-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:53-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: gsa.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:53-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:54-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:54-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: gsa.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:55-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:55-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:56-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: gsa.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:56-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:02:56-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:03:14-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: gsa.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:03:14-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746
    2018-11-16 13:03:15-05:00EST  "Server certificate validation failed: CERT_UNTRUSTED_ISSUER, Name in certificate: registration.ess.apple.com"  0 300000:1  te_transaction.cpp:1746

     

    Thank you!

     



  • 2.  RE: Unable to authenticate to InTune Company Portal

    Posted Nov 19, 2018 07:33 AM

    Hi,

     

                 It looks like these websites are using certificates signed by an Apple Owned CA which is not trusted by Proxy by default. We can come out of this by following one of the 3 methods mentioned in article https://support.symantec.com/content/unifiedweb/en_US/article.TECH243610.html . Looks like you are already doing the 3rd step mentioned in article.

     



  • 3.  RE: Unable to authenticate to InTune Company Portal

    Posted Nov 19, 2018 01:01 PM

    Thank you for the response. We added the certs and approved them. However, we're still having issues and we're still receiving "Company Portal Temporarily Unavailable - The Company portal encountered a problem" messages.



  • 4.  RE: Unable to authenticate to InTune Company Portal

    Posted Nov 19, 2018 11:41 PM

    Hi,

    Probably that issue is with server itself or it don’t like SSL Interception by any device in between. You may want to bypass SSL Interception for these domains and see whether that helps.