Re: EZproxy and strange intermittent browser cache/certificate errors
"Lolis, John" <[email protected]>
| Newsgroups | gmane.education.ezproxy |
|---|---|
| Message-ID | <CAJiSQLAWsif_9-hMwjkBLdRCyAAtrzFwW97cAWuXr2GzSz_M9g@mail.gmail.com> |
While the error in Chrome is legit based on the mismatch between your certificate and the URL, it almost sounds as if Chrome is doing a rewrite of its own in the background. One that clearing the cache corrects. I'd love to see what the access logs show coming from the server. I'd put money on it being correctly formatted. I've seen quite a few weird certificate errors lately, ones not actually attributable to the certificate. For example, I normally administer our Canon copiers through their browser UI; however, one of our copiers--the same model as the others--cannot be accessed using Vivaldi (and probably Chrome which I avoid like the plague). If I try to access it, I get: This site can’t provide a secure connection *172.16.0.193* doesn't adhere to security standards. ERR_SSL_SERVER_CERT_BAD_FORMAT Firefox has no such issue with it, and as I said, other Canon copiers of the same model *can *be accessed using Vivaldi. The certificate is also good until 2037. As for our certificate at https://whiteplainslibrary.org/, I run a test at https://www.ssllabs.com/ssltest/, and I save the results as a PDF. When someone says that their browser complains about our certificate (and it's happened), I show them a copy of those results that give our certificate an A rating. It's gotten to be that bad lately with browsers misreporting errors that I've taken to doing that. John Lolis Coordinator of Computer Systems 100 Martine Avenue White Plains, NY 10601 tel: 1.914.422.1497 fax: 1.914.422.1452 https://whiteplainslibrary.org/ *When you think about it, *all* security is ultimately security by ignorance.* On Tue, 22 Oct 2019 at 12:56, Matthew Anderson <[email protected]> wrote: > Hi All, > > We have had sporadic issues with off campus access through our EZproxy > server, where a student gets an error message claiming “Your connection is > not private” (Chrome) or “Your connection is not secure” (Firefox). > > > > Example error message from Chrome: > > [image: cid:[email protected]] > > > > A commonality of this issue I have noticed is that the URL doesn’t seem to > be a properly translated EZproxy subdomain. In the above image it should > be infotrac-galegroup-com.ezp.mhcc.edu (to match our *.ezp.mhcc.edu > wildcard certificate), but instead it’s trying to load > infotrac.galegroup.com.ezp.mhcc.edu (not substituting dots with hyphens). > > > > I have verified that the links followed were properly formatted ( > https://login.ezp.mhcc.edu/login?url=[resource]). It’s also not limited > to one specific resource, it happens for EBSCO/Gale/Etc. > > > > Clearing the browser cache fixes the issue for that user, but it’s > happening frequently enough that it’s become a significant nuisance. > > > > I contacted OCLC support and they suggested it might be an issue with the > certificate’s subject alternate name. I’m not sure if that completely > makes sense though, since clearing the browser cache removes the warning, > and ever certificate checker I’ve tried suggests it’s installed correctly > (see attached png). > > > > I’m wondering if others have experienced anything similar or have any > insight on what might be happening. > > > > Thanks very much, > > > > Matthew Anderson > > Library Technology Specialist > > Mt. Hood Community College > > > > ------------------------------ > > To unsubscribe from the EZPROXY-L list, click the following link: > http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1 > ******************************************************************** If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences, you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>. Or email [email protected] including the relevant text below in the body of the email: • To unsubscribe: "unsubscribe EZPROXY-L" • To receive EZPROXY-L in digest form: "set EZPROXY-L digest" • To set your options to no mail: "set EZPROXY-L nomail" • To receive these messages in the future "set EZPROXY-L mail" To contact the list owners directly please send your message to [email protected]. If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum. To unsubscribe from all OCLC marketing email communications (including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters), please email us at [email protected].
image001.jpg
(image/jpeg, 17.2 KB) - not displayed