SSO Authentication Fail
SSO Authentication Fail can interrupt web access, policy enforcement, or evidence collection. Use this runbook to restore service, preserve logs, and prove the corrective action during security review. If your configuration is exactly like How to and still your SSO authentication failed. Check out the following:- Make sure the User Name: is administrator@safesquid.test (User name should be any user from AD having administrative permissions)
- Monit service must be Up. Verify it using the command:
- As soon as you Save policy by selecting NEGOTIATE_LDAP_AUTH kerberos.sh* script will automatically run from path /usr/local/safesquid/ui_root/cgi-bin
- Go to Access Restriction > GLOBAL >> SSO: TRUE
- ALLOW List: Policy with PAM: TRUE
- Testing SSO Auth a. Go to the Windows machine which joins in the domain of AD e.g windows7.safesquid.test b. Go to the browser and set PROXY as FQDN of the proxy server (sabproxy.safesquid.test) c. Access any website (Authentication prompt should not come) d. Open extended logs
Capture useful evidence
Collect evidence before restarting services or changing policy. Keep screenshots, command output, and relevant SafeSquid logs with the incident ticket.Next steps
- Use Find a complete connection log to trace a specific client transaction.
- Use Troubleshooting for the broader diagnostic checklist.

