Re: O'Reilly / Safari EZproxy Shared Secret/Single Sign On
Laszlo Gercsov <[email protected]>
| Newsgroups | gmane.education.ezproxy |
|---|---|
| Message-ID | <MEAPR01MB5221656DE6EB5D295EC7D773D6890@MEAPR01MB5221.ausprd01.prod.outlook.com> |
Hi Roen. From your description, the O’Reilly site recognises the IP address range(s) allocated to your institution, and redirects users to your institution login page. Once a user provides valid credentials, your institution SAML server sends some information back to the O’Reilly server so that your session can be recognised. You need to ask your institution IT about the SAML configuration for O’Reilly, asking what information is provided to O’Reilly. In the best case, the information is only an encrypted identifier. In my experience, commonly the information includes name, email address, insitiution userID, and statistical categories for reporting pruposes. In any case, the service provider will know the users IP address and what content was accessed. You could look in https://www.whatismyip.com/ to see just how much is accessible from the service provider. Best, Laszlo. Laszlo Gercsov Senior Systems Analyst Library Systems Library | Level 4 16 Macquarie Drive Macquarie University, NSW 2109, Australia T: +61 2 9850 6533 | F: +61 2 9850 7568 M: + 61 402 175 101 | mq.edu.au/library<http://mq.edu.au/> [Macquarie University]<http://mq.edu.au/> CRICOS Provider Number 00002J. Think before you print. Please consider the environment before printing this email. This message is intended for the addressee named and may contain confidential information. If you are not the intended recipient, please delete it and notify the sender. Views expressed in this message are those of the individual sender, and are not necessarily the views of Macquarie University ________________________________ From: EZproxy List <[email protected]> on behalf of Roen Janyk <[email protected]> Sent: Thursday, 19 September 2019 2:11 PM To: [email protected] <[email protected]> Subject: Re: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On We were told when we switched from EZproxy auth to SSO SAML auth, that the email prompt was simply to match email domain to those we have provided O’Reilly, but no further identifiable information is passed on, and that emails are not saved (unless a student chooses to create a personal account with additional features). When the domain matches those on file for our account, users are taken to our normal (local) SSO system for authentication. Is this not the case? Being based in Canada, and BC at that, we have strict privacy laws related to where our user’s information is stored. We had too many authentication problems with the shared secret/EZproxy/SSO auth method so we moved forward with SAML. Roen Roën Janyk, BA MLIS Web Services Librarian Library Department Chair Okanagan College Kelowna, BC (250) 762-5445 x.4660 | L101A [email protected]<mailto:[email protected]> From: EZproxy List <[email protected]> On Behalf Of Caris Chamberlain Sent: Wednesday, September 18, 2019 7:16 PM To: [email protected] Subject: Re: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On Hello, We also use the EncrytVar u in our stanza to help with the privacy issue. I also force everyone to log into the proxy even if they are on campus for this database. This ensure they get their reading history and bookmarks instead of having a general history that covers multiple people browsing which was happening with auto login on campus. I have found that direct chapter linking can be a bit iffy but linking to the book level is fine. One issue we have is when we upload the Marc records into our library system it likes to turn the =^u into =Û which then breaks the authentication in the URL so that is something to maybe look out for. Kind Regards Caris Caris Chamberlain Senior Librarian, Subscriptions, Research and Resources, Murdoch University Library<https://protect-au.mimecast.com/s/BhZTCvl1g2S2rgxYtQTCFp?domain=library.murdoch.edu.au> 90 South Street, Murdoch, Western Australia 6150 • +61 8 9360 2520 • [email protected]<mailto:[email protected]> [murdoch university]<https://protect-au.mimecast.com/s/i_KcCwV1jpSAgQKquqXHN0?domain=murdoch.edu.au> I acknowledge that I live and work on Whadjuk Noongar Boodjar and pay respect to all Noongar people and Elders, past and present. From: EZproxy List <[email protected]<mailto:[email protected]>> On Behalf Of Melissa Belvadi Sent: Wednesday, 18 September 2019 12:23 AM To: [email protected]<mailto:[email protected]> Subject: Re: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On Thank you very much! That's just what we needed. I wish OCLC would add that to the official stanza for this product. Melissa Belvadi Collections Librarian University of Prince Edward Island [email protected]<mailto:[email protected]> 902-566-0581 my public calendar<https://protect-au.mimecast.com/s/cotNCxngGkf9P0k7IY1zG6?domain=google.com> Make an appointment<https://protect-au.mimecast.com/s/7PaZCyoj8Pu0AWZ8URg09S?domain=mbelvadi.youcanbook.me> via YouCanBookMe On Tue, Sep 17, 2019 at 1:10 PM Marconnet, Donna J <[email protected]<mailto:[email protected]>> wrote: We added encryptvar to the config code which I think should help encrypt the username which we did for privacy concerns. AllowVars u EncryptVar u (some encryption phrase here) see https://help.oclc.org/Library_Management/EZproxy/Configure_resources/EncryptVar<https://protect-au.mimecast.com/s/00LDCzvkmpfxOB6kIoRyJk?domain=help.oclc.org> Donna Donna Marconnet Library Technology Coordinator Madison Area Technical College Libraries [email protected]<mailto:[email protected]> 608-243-4085 From: EZproxy List <[email protected]<mailto:[email protected]>> On Behalf Of Melissa Belvadi Sent: Tuesday, September 17, 2019 10:51 AM To: [email protected]<mailto:[email protected]> Subject: Re: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On Reinforce what Donna said. O'Reilly support really wants you to use the email address authentication system. We really don't want to because of privacy. However, we do have to use the "additional code" at the end and recently found out that what it's doing is sending our user's username to them, which is basically the same privacy violation so not sure what to do next. I emailed this list about that problem recently but didn't get any answers so I'm guessing no one else has a good solution for it. Also if you use this method, you'll find you can't use the playlist sharing functions because those links don't have the suffix and won't work. Likewise, patrons won't be able to just copy the address bar URL, which looks like it ought to be a good persistent link (ie no weird session codes). Or more likely, they'll do it and then be confused later that it doesn't work. I've put together a little form to help them fix it, but not sure how to tell people about it, so it's mostly just for staff right now. https://library.upei.ca/safari-oreilly-persistent-chapter-links<https://protect-au.mimecast.com/s/ksa3CBNqgBCMzmjwFvD_ik?domain=nam01.safelinks.protection.outlook.com> Melissa Belvadi Collections Librarian University of Prince Edward Island [email protected]<mailto:[email protected]> 902-566-0581 my public calendar<https://protect-au.mimecast.com/s/hqhJCD1vRkCnDmqEIBD4aI?domain=nam01.safelinks.protection.outlook.com> Make an appointment<https://protect-au.mimecast.com/s/3xDGCE8wlRCgkGLvhyIsAM?domain=nam01.safelinks.protection.outlook.com> via YouCanBookMe On Tue, Sep 17, 2019 at 9:13 AM Marconnet, Donna J <[email protected]<mailto:[email protected]>> wrote: We use ezproxy shared secret for O'Reilly authentication and we chose to use encryptvar too. It didn't take a year. It did take longer than expected though. Here's some things we learned along the way: There are 3 options for authentication and from my experience, technical support at O'Reilly is not a fan of ezproxy. They prefer you use something else. You have to construct permalinks/stable URLs manually by adding the ezproxy prefix at the start as well as additional code at the end of the URL. If we don't have the extra code at the end, users aren't authenticated. So that's been a challenge. Also the share button won't work because of this. It took a while for O'Reilly to be a discoverable collection in our Discovery system, but that is now available. We are concerned that many videos are not closed captioned. They have a cc play button but are not captioned. Response from O'Reilly has not been satisfactory on this issue. Donna Donna Marconnet Library Technology Coordinator Madison Area Technical College Truax Rm. A3000, 608-243-4085 [email protected]<mailto:[email protected]> ________________________________ From: EZproxy List <[email protected]<mailto:[email protected]>> on behalf of Adam Pinfold <[email protected]<mailto:[email protected]>> Sent: Tuesday, September 17, 2019 3:48 AM To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>> Subject: [EZPROXY-L] O'Reilly / Safari EZproxy Shared Secret/Single Sign On Hi all We’ve recently been told by O’Reilly that we can’t use the OCLC Safari Books Online stanza anymore and now need to use their EZproxy Shared Secret/Single Sign On method. I’ve just been checking through emails to this group though and finding some worrying accounts of this taking a year to set up and still not working properly! Does anyone have any current positive or negative experiences of this new method, as would really appreciate hearing them before going ahead with this? Please contact me off-list if you prefer. All the best Adam Adam Pinfold | Engineer (Library Systems) | Learning and Research Systems IT Services, University of the West of England, Coldharbour Lane, Bristol BS16 1QY Tel: +44 (0)117 32 82548 ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/uf0gCJyBZ6t1gzZ6cn5G9B?domain=nam01.safelinks.protection.outlook.com> ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/lelcCK1DOrCBZwOXCr7WxP?domain=nam01.safelinks.protection.outlook.com> ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/uf0gCJyBZ6t1gzZ6cn5G9B?domain=nam01.safelinks.protection.outlook.com> ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/CQCECGv0Z6f02lkDUWVsYH?domain=listserv.oclclists.org> ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/CQCECGv0Z6f02lkDUWVsYH?domain=listserv.oclclists.org> ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/CQCECGv0Z6f02lkDUWVsYH?domain=listserv.oclclists.org> ******************************************************************** If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences, you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>. Or email [email protected] including the relevant text below in the body of the email: • To unsubscribe: "unsubscribe EZPROXY-L" • To receive EZPROXY-L in digest form: "set EZPROXY-L digest" • To set your options to no mail: "set EZPROXY-L nomail" • To receive these messages in the future "set EZPROXY-L mail" To contact the list owners directly please send your message to [email protected]. If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum. To unsubscribe from all OCLC marketing email communications (including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters), please email us at [email protected].
image001.png
(image/png, 39.4 KB) - not displayed