Re: EZproxy and strange intermittent browser cache/certificate errors

Matthew Anderson <[email protected]>
Newsgroups gmane.education.ezproxy
Message-ID <[email protected]>
Very interesting, I will read up on that a bit.
Thanks very much,
-Matt

From: Tom Misilo <[email protected]>
Sent: Wednesday, October 23, 2019 7:07 AM
To: [email protected]
Cc: Matthew Anderson <[email protected]>
Subject: RE: EZproxy and strange intermittent browser cache/certificate errors

External Email
“Incidentally, did your ITS department have any idea as to the root cause?”

My guess on the root cause is on one of the servers with a mhcc.edu SSL certificate HSTS was probably configured with includeDomains. For more information this site looks good (https://www.danielmorell.com/blog/how-to-configure-hsts-on-www-and-other-subdomains).

Tom

From: Matthew Anderson <[email protected]<mailto:[email protected]>>
Sent: Tuesday, October 22, 2019 1:28 PM
Subject: Re: EZproxy and strange intermittent browser cache/certificate errors

Hi Marcie,
Thanks for the information.  I have been advising affected students to clear their browser cache (see attached), but clearing the HSTS settings for mhcc.edu might be a less dramatic fix in the interim.  I’m hesitant to recommend Internet Explorer in general, but for students with a Windows PC it’s good to have another option.
Incidentally, did your ITS department have any idea as to the root cause?
Thanks very much,
-Matt

From: Marcie Burton <[email protected]<mailto:[email protected]>>
Sent: Tuesday, October 22, 2019 10:22 AM
To: Matthew Anderson <[email protected]<mailto:[email protected]>>
Cc: [email protected]<mailto:[email protected]>
Subject: Re: [EZPROXY-L] EZproxy and strange intermittent browser cache/certificate errors

External Email
We had a similar issue in October of last year related to https vs. http and other issues we had no control over due to our ITS department's decisions. Our patrons were seeing a security exception and being told the site is not secure. This happened on Chrome, Firefox and Safari.  It didn't seem to be happening on Internet Explorer.  This is causing problems because often these sites are created by external parties (like publishers) and have http content that we cannot change.

There are a few solutions:
1. Ask for them to use Internet Explorer to access the problematic resource.
2. Use the instructions below to hopefully fix the issue.  Instructions have been provided for all three browsers.

See our instructions below.

Marcie

On Tue, Oct 22, 2019 at 12:55 PM Matthew Anderson <[email protected]<mailto:[email protected]>> wrote:
Hi All,
We have had sporadic issues with off campus access through our EZproxy server, where a student gets an error message claiming “Your connection is not private” (Chrome) or “Your connection is not secure” (Firefox).

Example error message from Chrome:
[cid:[email protected]]

A commonality of this issue I have noticed is that the URL doesn’t seem to be a properly translated EZproxy subdomain.  In the above image it should be infotrac-galegroup-com.ezp.mhcc.edu<http://infotrac-galegroup-com.ezp.mhcc.edu> (to match our *.ezp.mhcc.edu<http://ezp.mhcc.edu> wildcard certificate), but instead it’s trying to load infotrac.galegroup.com.ezp.mhcc.edu<http://infotrac.galegroup.com.ezp.mhcc.edu> (not substituting dots with hyphens).

I have verified that the links followed were properly formatted (https://login.ezp.mhcc.edu/login?url=[resource]<https://login.ezp.mhcc.edu/login?url=%5bresource%5d>).  It’s also not limited to one specific resource, it happens for EBSCO/Gale/Etc.

Clearing the browser cache fixes the issue for that user, but it’s happening frequently enough that it’s become a significant nuisance.

I contacted OCLC support and they suggested it might be an issue with the certificate’s subject alternate name.  I’m not sure if that completely makes sense though, since clearing the browser cache removes the warning, and ever certificate checker I’ve tried suggests it’s installed correctly (see attached png).

I’m wondering if others have experienced anything similar or have any insight on what might be happening.

Thanks very much,

Matthew Anderson
Library Technology Specialist
Mt. Hood Community College


________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1


--
Marcie Burton
Electronic Resources Cataloging Technician
The University of North Carolina at Greensboro
Technical Services Department
Walter Clinton Jackson Library
P.O. Box 26170
Greensboro, NC 27402-6170
Phone: 336.265.7489 or 336.334.5781
[email protected]<mailto:[email protected]>

[https://docs.google.com/uc?export=download&id=1qDNAKX51rZ0MqNOWAETz-Mx3cuYgnIDn&revid=0B8IO8PX8Y7VHQ09lMm5EWlJmcG85U3dGd1RzeVFZdEdTSDQ4PQ]


________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1

********************************************************************
If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences,
you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>.
Or email [email protected] including the relevant text below in the body of the email:
• To unsubscribe: "unsubscribe EZPROXY-L"
• To receive EZPROXY-L in digest form: "set EZPROXY-L digest"
• To set your options to no mail: "set EZPROXY-L nomail"
• To receive these messages in the future "set EZPROXY-L mail"
To contact the list owners directly please send your message to [email protected].
If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum.
To unsubscribe from all OCLC marketing email communications
(including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters),
please email us at [email protected].
image001.jpg (image/jpeg, 17.2 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.