Re: EZproxy and strange intermittent browser cache/certificate errors

Matthew Anderson <[email protected]>
Newsgroups gmane.education.ezproxy
Message-ID <[email protected]>
That’s a good point, the next time somebody reports this issue I’ll see if they can give me an approximate time so I can look over the logs for that period.  I wish I knew some way to consistently trigger this error, but so far the root cause has been too elusive to track down.
Thank you much,
-Matt

From: EZproxy List <[email protected]> On Behalf Of Lolis, John
Sent: Tuesday, October 22, 2019 12:28 PM
To: [email protected]
Subject: Re: [EZPROXY-L] EZproxy and strange intermittent browser cache/certificate errors

External Email
While the error in Chrome is legit based on the mismatch between your certificate and the URL, it almost sounds as if Chrome is doing a rewrite of its own in the background.  One that clearing the cache corrects.  I'd love to see what the access logs show coming from the server.  I'd put money on it being correctly formatted.

I've seen quite a few weird certificate errors lately, ones not actually attributable to the certificate.  For example, I normally administer our Canon copiers through their browser UI; however, one of our copiers--the same model as the others--cannot be accessed using Vivaldi (and probably Chrome which I avoid like the plague).  If I try to access it, I get:

This site can’t provide a secure connection

172.16.0.193 doesn't adhere to security standards.
ERR_SSL_SERVER_CERT_BAD_FORMAT

Firefox has no such issue with it, and as I said, other Canon copiers of the same model can be accessed using Vivaldi.  The certificate is also good until 2037.

As for our certificate at https://whiteplainslibrary.org/, I run a test at https://www.ssllabs.com/ssltest/, and I save the results as a PDF.  When someone says that their browser complains about our certificate (and it's happened), I show them a copy of those results that give our certificate an A rating.  It's gotten to be that bad lately with browsers misreporting errors that I've taken to doing that.

John Lolis
Coordinator of Computer Systems
[https://drive.google.com/a/whiteplainsny.gov/uc?id=0B8o3RoemjyAfR1hZV1U0SWJDdGs&export=download]
100 Martine Avenue
White Plains, NY  10601

tel: 1.914.422.1497
fax: 1.914.422.1452

https://whiteplainslibrary.org/

When you think about it, all security is ultimately security by ignorance.



On Tue, 22 Oct 2019 at 12:56, Matthew Anderson <[email protected]<mailto:[email protected]>> wrote:
Hi All,
We have had sporadic issues with off campus access through our EZproxy server, where a student gets an error message claiming “Your connection is not private” (Chrome) or “Your connection is not secure” (Firefox).

Example error message from Chrome:
[cid:[email protected]]

A commonality of this issue I have noticed is that the URL doesn’t seem to be a properly translated EZproxy subdomain.  In the above image it should be infotrac-galegroup-com.ezp.mhcc.edu<http://infotrac-galegroup-com.ezp.mhcc.edu> (to match our *.ezp.mhcc.edu<http://ezp.mhcc.edu> wildcard certificate), but instead it’s trying to load infotrac.galegroup.com.ezp.mhcc.edu<http://infotrac.galegroup.com.ezp.mhcc.edu> (not substituting dots with hyphens).

I have verified that the links followed were properly formatted (https://login.ezp.mhcc.edu/login?url=[resource]<https://login.ezp.mhcc.edu/login?url=%5bresource%5d>).  It’s also not limited to one specific resource, it happens for EBSCO/Gale/Etc.

Clearing the browser cache fixes the issue for that user, but it’s happening frequently enough that it’s become a significant nuisance.

I contacted OCLC support and they suggested it might be an issue with the certificate’s subject alternate name.  I’m not sure if that completely makes sense though, since clearing the browser cache removes the warning, and ever certificate checker I’ve tried suggests it’s installed correctly (see attached png).

I’m wondering if others have experienced anything similar or have any insight on what might be happening.

Thanks very much,

Matthew Anderson
Library Technology Specialist
Mt. Hood Community College


________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1

________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1

********************************************************************
If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences,
you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>.
Or email [email protected] including the relevant text below in the body of the email:
• To unsubscribe: "unsubscribe EZPROXY-L"
• To receive EZPROXY-L in digest form: "set EZPROXY-L digest"
• To set your options to no mail: "set EZPROXY-L nomail"
• To receive these messages in the future "set EZPROXY-L mail"
To contact the list owners directly please send your message to [email protected].
If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum.
To unsubscribe from all OCLC marketing email communications
(including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters),
please email us at [email protected].
image001.jpg (image/jpeg, 17.2 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.