Re: WildCard Cert Errors

John Benedetto <[email protected]>
Newsgroups gmane.education.ezproxy
Message-ID <DM6PR07MB5321A50870EB112715BAD659C5950@DM6PR07MB5321.namprd07.prod.outlook.com>
Andreas,

Don't forget to put these directives in your config.txt:
Option ForceHTTPSAdmin
Option ForceHTTPSLogin

The ForceHTTPSLogin automatically turns this:
http://ezproxy.foo.com/login?url=https://www.referenceusa.com 
into:
https://ezproxy.foo.com/login?url=https://www.referenceusa.com 
So the user does not try to login with an insecure page.

The best way to go is with what you call the complex cert - one that covers *.foo.ezproxy.com, but also has a SAN entry for foo.ezproxy.com.  While you CAN go without the SAN entry (we did so for YEARS), having the SAN entry on your cert covers the occasional user or situation that pops an error, since you cannot control what your users will try or configure, etc.  

As well, having the SAN entry for foo.ezproxy.com makes it so this:
https://ezproxy.foo.com/login?url=https://www.referenceusa.com
does not cause an error for the user.

John

-----Original Message-----
From: EZproxy List <[email protected]> On Behalf Of Bohne-Lang, Andreas
Sent: Tuesday, October 8, 2019 11:23 PM
To: [email protected]
Subject: Re: [EZPROXY-L] WildCard Cert Errors

Dear Vivien,

thank you for your post and pointing out that

https://login.ezproxy.foo.com/login?url=https://www.referenceusa.com

is equal to

http://ezproxy.foo.com/login?url=https://www.referenceusa.com

We use a simple wildcard cert and I was always looking for a way to fix the missing https at the login host. You did it :-) Thank you!

Greetings

Andreas

Summary:

1) Simple wildcard cert: 
https://login.ezproxy.foo.com/login?url=https://www.referenceusa.com -> best way

2) Simple wildcard cert: 
http://ezproxy.foo.com/login?url=https://www.referenceusa.com -> working but insecure because it only uses http and not https

3) Complex wildcard cert: 
https://ezproxy.foo.com/login?url=https://www.referenceusa.com -> you need a wildcard cert with an alias / alternativ CN for the ezproxy.foo.com host


********************************************************************
If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences,
you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>.
Or email [email protected] including the relevant text below in the body of the email:
• To unsubscribe: "unsubscribe EZPROXY-L"
• To receive EZPROXY-L in digest form: "set EZPROXY-L digest"
• To set your options to no mail: "set EZPROXY-L nomail"
• To receive these messages in the future "set EZPROXY-L mail"
To contact the list owners directly please send your message to [email protected].
If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum.
To unsubscribe from all OCLC marketing email communications
(including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters),
please email us at [email protected].
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.