Re: O'Reilly / Safari EZproxy Shared Secret/Single Sign On

Laszlo Gercsov <[email protected]>
Newsgroups gmane.education.ezproxy
Message-ID <MEAPR01MB5221656DE6EB5D295EC7D773D6890@MEAPR01MB5221.ausprd01.prod.outlook.com>
Hi Roen.

From your description, the O’Reilly site recognises the IP address range(s) allocated to your institution, and redirects users to your institution login page.
Once a user provides valid credentials, your institution SAML server sends some information back to the O’Reilly server so that your session can be recognised.

You need to ask your institution IT about the SAML configuration for O’Reilly, asking what information is provided to O’Reilly.

In the best case, the information is only an encrypted identifier. In my experience, commonly the information includes name, email address, insitiution userID, and statistical categories for reporting pruposes.

In any case, the service provider will know the users IP address and what content was accessed. You could look in https://www.whatismyip.com/ to see just how much is accessible from the service provider.

Best,

Laszlo.


Laszlo Gercsov

Senior Systems Analyst Library Systems

Library  |  Level 4
16 Macquarie Drive
Macquarie University, NSW 2109, Australia

T: +61 2 9850 6533 | F: +61 2 9850 7568

M: + 61 402 175 101  |  mq.edu.au/library<http://mq.edu.au/>

[Macquarie University]<http://mq.edu.au/>

CRICOS Provider Number 00002J. Think before you print.
Please consider the environment before printing this email.

This message is intended for the addressee named and may
contain confidential information. If you are not the intended
recipient, please delete it and notify the sender. Views expressed
in this message are those of the individual sender, and are not
necessarily the views of Macquarie University

________________________________
From: EZproxy List <[email protected]> on behalf of Roen Janyk <[email protected]>
Sent: Thursday, 19 September 2019 2:11 PM
To: [email protected] <[email protected]>
Subject: Re: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On


We were told when we switched from EZproxy auth to SSO SAML auth, that the email prompt was simply to match email domain to those we have provided O’Reilly, but no further identifiable information is passed on, and that emails are not saved (unless a student chooses to create a personal account with additional features). When the domain matches those on file for our account, users are taken to our normal (local) SSO system for authentication. Is this not the case? Being based in Canada, and BC at that, we have strict privacy laws related to where our user’s information is stored. We had too many authentication problems with the shared secret/EZproxy/SSO auth method so we moved forward with SAML.



Roen





Roën Janyk, BA MLIS

Web Services Librarian

Library Department Chair

Okanagan College

Kelowna, BC

(250) 762-5445 x.4660 | L101A

[email protected]<mailto:[email protected]>







From: EZproxy List <[email protected]> On Behalf Of Caris Chamberlain
Sent: Wednesday, September 18, 2019 7:16 PM
To: [email protected]
Subject: Re: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On



Hello,



We also use the EncrytVar u in our stanza to help with the privacy issue. I also force everyone to log into the proxy even if they are on campus for this database. This ensure they get their reading history and bookmarks instead of having a general history that covers multiple people browsing which was happening with auto login on campus.



I have found that direct chapter linking can be a bit iffy but linking to the book level is fine.



One issue we have is when we upload the Marc records into our library system it likes to turn the =^u into =Û which then breaks the authentication in the URL so that is something to maybe look out for.



Kind Regards

Caris



Caris Chamberlain

Senior Librarian, Subscriptions, Research and Resources, Murdoch University Library<https://protect-au.mimecast.com/s/BhZTCvl1g2S2rgxYtQTCFp?domain=library.murdoch.edu.au>



90 South Street, Murdoch, Western Australia 6150    • +61 8 9360 2520  •  [email protected]<mailto:[email protected]>



[murdoch university]<https://protect-au.mimecast.com/s/i_KcCwV1jpSAgQKquqXHN0?domain=murdoch.edu.au>



I acknowledge that I live and work on Whadjuk Noongar Boodjar and pay respect to all Noongar people and Elders, past and present.







From: EZproxy List <[email protected]<mailto:[email protected]>> On Behalf Of Melissa Belvadi
Sent: Wednesday, 18 September 2019 12:23 AM
To: [email protected]<mailto:[email protected]>
Subject: Re: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On



Thank you very much! That's just what we needed. I wish OCLC would add that to the official stanza for this product.



Melissa Belvadi

Collections Librarian

University of Prince Edward Island

[email protected]<mailto:[email protected]>  902-566-0581

my public calendar<https://protect-au.mimecast.com/s/cotNCxngGkf9P0k7IY1zG6?domain=google.com>

Make an appointment<https://protect-au.mimecast.com/s/7PaZCyoj8Pu0AWZ8URg09S?domain=mbelvadi.youcanbook.me> via YouCanBookMe









On Tue, Sep 17, 2019 at 1:10 PM Marconnet, Donna J <[email protected]<mailto:[email protected]>> wrote:

We added encryptvar to the config code which I think should help encrypt the username which we did for privacy concerns.



AllowVars u
EncryptVar u (some encryption phrase here)

see https://help.oclc.org/Library_Management/EZproxy/Configure_resources/EncryptVar<https://protect-au.mimecast.com/s/00LDCzvkmpfxOB6kIoRyJk?domain=help.oclc.org>



Donna



Donna Marconnet

Library Technology Coordinator

Madison Area Technical College Libraries

[email protected]<mailto:[email protected]>

608-243-4085





From: EZproxy List <[email protected]<mailto:[email protected]>> On Behalf Of Melissa Belvadi
Sent: Tuesday, September 17, 2019 10:51 AM
To: [email protected]<mailto:[email protected]>
Subject: Re: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On



Reinforce what Donna said. O'Reilly support really wants you to use the email address authentication system. We really don't want to because of privacy.  However, we do have to use the "additional code" at the end and recently found out that what it's doing is sending our user's username to them, which is basically the same privacy violation so not sure what to do next.  I emailed this list about that problem recently but didn't get any answers so I'm guessing no one else has a good solution for it.

Also if you use this method, you'll find you can't use the playlist sharing functions because those links don't have the suffix and won't work.

Likewise, patrons won't be able to just copy the address bar URL, which looks like it ought to be a good persistent link (ie no weird session codes).

Or more likely, they'll do it and then be confused later that it doesn't work.

I've put together a little form to help them fix it, but not sure how to tell people about it, so it's mostly just for staff right now.

https://library.upei.ca/safari-oreilly-persistent-chapter-links<https://protect-au.mimecast.com/s/ksa3CBNqgBCMzmjwFvD_ik?domain=nam01.safelinks.protection.outlook.com>





Melissa Belvadi

Collections Librarian

University of Prince Edward Island

[email protected]<mailto:[email protected]>  902-566-0581

my public calendar<https://protect-au.mimecast.com/s/hqhJCD1vRkCnDmqEIBD4aI?domain=nam01.safelinks.protection.outlook.com>

Make an appointment<https://protect-au.mimecast.com/s/3xDGCE8wlRCgkGLvhyIsAM?domain=nam01.safelinks.protection.outlook.com> via YouCanBookMe









On Tue, Sep 17, 2019 at 9:13 AM Marconnet, Donna J <[email protected]<mailto:[email protected]>> wrote:

We use ezproxy shared secret for O'Reilly authentication  and we chose to use encryptvar too. It didn't take a year.  It did take longer than expected though. Here's some things we learned along the way:



There are 3 options for authentication and from my experience, technical support at O'Reilly is not a fan of ezproxy. They prefer you use something else.

You have to construct permalinks/stable URLs manually by adding the ezproxy prefix at the start as well as additional code at the end of the URL. If we don't have the extra code at the end, users aren't authenticated. So that's been a challenge.  Also the share button won't work because of this.

It took a while for O'Reilly to be a discoverable collection in our Discovery system, but that is now available.

We are concerned that many videos are not closed captioned. They have a cc play button but are not captioned. Response from O'Reilly has not been satisfactory on this issue.



Donna



Donna Marconnet
Library Technology Coordinator
Madison Area Technical College
Truax Rm. A3000, 608-243-4085
[email protected]<mailto:[email protected]>

________________________________

From: EZproxy List <[email protected]<mailto:[email protected]>> on behalf of Adam Pinfold <[email protected]<mailto:[email protected]>>
Sent: Tuesday, September 17, 2019 3:48 AM
To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>>
Subject: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On



Hi all



We’ve recently been told by O’Reilly that we can’t use the OCLC Safari Books Online stanza anymore and now need to use their EZproxy Shared Secret/Single Sign On method.



I’ve just been checking through emails to this group though and finding some worrying accounts of this taking a year to set up and still not working properly!



Does anyone have any current positive or negative experiences of this new method, as would really appreciate hearing them before going ahead with this? Please contact me off-list if you prefer.



All the best

Adam



Adam Pinfold | Engineer (Library Systems) | Learning and Research Systems

IT Services, University of the West of England, Coldharbour Lane, Bristol BS16 1QY



Tel: +44 (0)117 32 82548





________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/uf0gCJyBZ6t1gzZ6cn5G9B?domain=nam01.safelinks.protection.outlook.com>



________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/lelcCK1DOrCBZwOXCr7WxP?domain=nam01.safelinks.protection.outlook.com>



________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/uf0gCJyBZ6t1gzZ6cn5G9B?domain=nam01.safelinks.protection.outlook.com>



________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/CQCECGv0Z6f02lkDUWVsYH?domain=listserv.oclclists.org>



________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/CQCECGv0Z6f02lkDUWVsYH?domain=listserv.oclclists.org>

________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/CQCECGv0Z6f02lkDUWVsYH?domain=listserv.oclclists.org>

********************************************************************
If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences,
you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>.
Or email [email protected] including the relevant text below in the body of the email:
• To unsubscribe: "unsubscribe EZPROXY-L"
• To receive EZPROXY-L in digest form: "set EZPROXY-L digest"
• To set your options to no mail: "set EZPROXY-L nomail"
• To receive these messages in the future "set EZPROXY-L mail"
To contact the list owners directly please send your message to [email protected].
If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum.
To unsubscribe from all OCLC marketing email communications
(including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters),
please email us at [email protected].
image001.png (image/png, 39.4 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.