It seems dansguardian is no longer checking the groups of a user. It seems to always use the default group.
My default group in dansguardian is configured to only allow a whitelist:
dansguardian/groups/dansguardian_white/exception/sites .Include</etc/dansguardian/white/domains> .Include</etc/dansguardian/BL/updatesites/domains>
I just restored to Univention 4.4.0 and there I see in /var/log/dansguardian/access.log the normal behavior. When I browse to google.de I see my name and the group dansguardian_unrestricted.
So I repeated the upgrade to 4.4.1, joined the domain again and rebooted the server. And now I see a deny in the logs. The group is no longer dansguardian_unrestricted but the default group dansguardian_white.
I already followed the steps memberOf:
So I downgraded again to 4.4.0 and stopped the unattended upgrades.