Re: WildCard Cert Errors

Laszlo Gercsov <[email protected]>
Newsgroups gmane.education.ezproxy
Message-ID <MEAPR01MB52219873EBB92C0370B59788D69E0@MEAPR01MB5221.ausprd01.prod.outlook.com>
Hi Stephen.

Are you still getting those certificate errors ? I just checked again and successfully reached :-

https://www-jstor-org.ezproxy.gc.cuny.edu/action/showAdvancedSearch

In any case, to use HTTPS on thos URLs, you should have a certificate with :-

CN *.ezproxy.gc.cuny.edu
SAN ezproxy.gc.cuny.edu

I checked the jstor url above this morning with no certificate error, so I viewed the certificate and you already have the CN and SAN entries for 4 servers - see below.

Best,

Laszlo.


[cid:a72ff774-841a-4ff7-9229-4eacc3a08cb5]

________________________________
From: EZproxy List <[email protected]> on behalf of Klein, Stephen <[email protected]>
Sent: Thursday, 3 October 2019 11:31 PM
To: [email protected] <[email protected]>
Subject: Re: [EZPROXY-L] WildCard Cert Errors


Thanks, Lazlo.  How should I re-do the cert so I can use:

https://ezproxy.gc.cuny.edu<https://protect-au.mimecast.com/s/EeBKCgZ05JfmrOK7INi9o_?domain=ezproxy.gc.cuny.edu>

because all my dbs are set to this form

https://ezproxy.gc.cuny.edu/login?url=https://www.jstor.org/action/showAdvancedSearch<https://protect-au.mimecast.com/s/zR6UCjZ12Rf32KDvIR2VNl?domain=ezproxy.gc.cuny.edu>







From: Laszlo Gercsov <[email protected]>
Sent: Wednesday, October 2, 2019 7:52 PM
To: Klein, Stephen <[email protected]>; [email protected]
Subject: Re: WildCard Cert Errors



Hi Stephen.



Your wildcard certificate is set up like mine. Your certificate only has :-



Common Name (CN) *.ezproxy.gc.cuny.edu



That means that the certificate will not match https://ezproxy.gc.cuny.edu<https://protect-au.mimecast.com/s/EeBKCgZ05JfmrOK7INi9o_?domain=ezproxy.gc.cuny.edu> - you need to use https://login.ezproxy.gc.cuny.edu<https://protect-au.mimecast.com/s/jl6KCk815RCr78ApiQobFs?domain=login.ezproxy.gc.cuny.edu> or http://ezproxy.gc.cuny.edu<https://protect-au.mimecast.com/s/G4V8Clx1OYUAy0mvhq90oT?domain=ezproxy.gc.cuny.edu>



Also, the wildcard "*" asterisk part of the certificate will only match one "word" in the URL ie no dots. Ezproxy will rewrite HTTPS urls replacing the dots in the vendor hostname with "-" hyphens.



Your starting point URLs should be either :-

http://ezproxy.gc.cuny.edu/login?url=https://www.jstor.org/action/showAdvancedSearch<https://protect-au.mimecast.com/s/2bWnCmO5wZsAZB8rhQLmbT?domain=ezproxy.gc.cuny.edu>

or

https://login.ezproxy.gc.cuny.edu/login?url=https://www.jstor.org/action/showAdvancedSearch<https://protect-au.mimecast.com/s/EqipCnx1Z5UKzAgYhEN8pD?domain=login.ezproxy.gc.cuny.edu>



Either way, the proxied URL will be rewritten by ezproxy to :-



https://www-jstor-org.ezproxy.gc.cuny.edu/action/showAdvancedSearch<https://protect-au.mimecast.com/s/syveCoV1Y2SBMj50IWs4Bv?domain=www-jstor-org.ezproxy.gc.cuny.edu>



Best,



Laszlo.





________________________________

From: EZproxy List <[email protected]<mailto:[email protected]>> on behalf of Klein, Stephen <[email protected]<mailto:[email protected]>>
Sent: Wednesday, 2 October 2019 10:42 PM
To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>>
Subject: Re: [EZPROXY-L] WildCard Cert Errors



Meant:

https://www.jstor.org.ezproxy.gc.cuny.edu/action/showAdvancedSearch [protect-au.mimecast.com]<https://protect-au.mimecast.com/s/wflWCq71jxfzDKnouMCVqp?domain=urldefense.proofpoint.com>

causes wildcard errors



From: Klein, Stephen <[email protected]<mailto:[email protected]>>
Sent: Tuesday, October 1, 2019 9:36 PM
To: [email protected]<mailto:[email protected]>
Subject: WildCard Cert Errors



The following URL causes no issues:

https://ezproxy.gc.cuny.edu/login?url=https://www.jstor.org/action/showAdvancedSearch [protect-au.mimecast.com]<https://protect-au.mimecast.com/s/pHRnCr810kC1pP7GcxIePm?domain=urldefense.proofpoint.com>

Which allows this Option HttpsHyphens​



This:

https://www-jstor-org.ezproxy.gc.cuny.edu/action/showAdvancedSearch [protect-au.mimecast.com]<https://protect-au.mimecast.com/s/fvMyCvl1g2S2Gpq3UWhv6f?domain=urldefense.proofpoint.com>

Causes Wildcard errors



Is the second URL allowed if using a WildCard Cert or it will always cause errors?



Thanks,

Stephen Klein

Graduate Center

​



________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1 [protect-au.mimecast.com]<https://protect-au.mimecast.com/s/P8TNCxngGkf9ynD3I409J1?domain=urldefense.proofpoint.com>

________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/DppBCwV1jpSA7JkWh4x_0B?domain=listserv.oclclists.org>

********************************************************************
If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences,
you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>.
Or email [email protected] including the relevant text below in the body of the email:
• To unsubscribe: "unsubscribe EZPROXY-L"
• To receive EZPROXY-L in digest form: "set EZPROXY-L digest"
• To set your options to no mail: "set EZPROXY-L nomail"
• To receive these messages in the future "set EZPROXY-L mail"
To contact the list owners directly please send your message to [email protected].
If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum.
To unsubscribe from all OCLC marketing email communications
(including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters),
please email us at [email protected].
image.png (image/png, 28.1 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.