<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity agent no SSO after hardening in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-agent-no-SSO-after-hardening/m-p/120033#M16991</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since we have hardened our Windows 10 systems we noticed that the identity agent is no longer automatically logging in.&lt;/P&gt;&lt;P&gt;First we thought this had something to do with the network discovery so we've configured the server (gateway) manually within the agent. However no change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for information on the "inner workings" of the agent to find out why the user is not able to SSO directly. We have tested on laptop system with cached credentials still enabled but the same issue occurs.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jun 2021 07:49:41 GMT</pubDate>
    <dc:creator>Tom_Heesmans</dc:creator>
    <dc:date>2021-06-01T07:49:41Z</dc:date>
    <item>
      <title>Identity agent no SSO after hardening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-agent-no-SSO-after-hardening/m-p/120033#M16991</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since we have hardened our Windows 10 systems we noticed that the identity agent is no longer automatically logging in.&lt;/P&gt;&lt;P&gt;First we thought this had something to do with the network discovery so we've configured the server (gateway) manually within the agent. However no change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for information on the "inner workings" of the agent to find out why the user is not able to SSO directly. We have tested on laptop system with cached credentials still enabled but the same issue occurs.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 07:49:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-agent-no-SSO-after-hardening/m-p/120033#M16991</guid>
      <dc:creator>Tom_Heesmans</dc:creator>
      <dc:date>2021-06-01T07:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity agent no SSO after hardening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-agent-no-SSO-after-hardening/m-p/120066#M16992</link>
      <description>&lt;P&gt;What precise steps did you take to harden Windows 10?&lt;BR /&gt;Tagging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;also.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 13:43:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-agent-no-SSO-after-hardening/m-p/120066#M16992</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-01T13:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity agent no SSO after hardening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-agent-no-SSO-after-hardening/m-p/120067#M16993</link>
      <description>&lt;P&gt;We did a lot, &amp;lt;correction&amp;gt; we applied CIS level 1.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 14:44:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-agent-no-SSO-after-hardening/m-p/120067#M16993</guid>
      <dc:creator>Tom_Heesmans</dc:creator>
      <dc:date>2021-06-01T14:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity agent no SSO after hardening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-agent-no-SSO-after-hardening/m-p/120302#M17040</link>
      <description>&lt;P&gt;I suggest checking this thread:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Management/When-will-AES-256-AES-128-Kerberos-cipher-suites-finally-be/td-p/2941" target="_blank"&gt;https://community.checkpoint.com/t5/Management/When-will-AES-256-AES-128-Kerberos-cipher-suites-finally-be/td-p/2941&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I guess your hardening disabled some legacy ciphers for Kerberos on your clients, so you have to adjust Identity Awareness config to use modern ciphers your client still supports.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/IDAG/pdp-auth.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/IDAG/pdp-auth.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 14:51:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-agent-no-SSO-after-hardening/m-p/120302#M17040</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-06-03T14:51:53Z</dc:date>
    </item>
  </channel>
</rss>

