Edith List | 1 Jul 2011 03:02

SSL Wildcard Certificates from ipsCA for JSTOR secure access

I received a wildcard certificate for our Ezproxy from IpsCa.  I and our IT staff have checked and double checked that the certificate is correctly installed along with the intermediate certificatesl.  However, only IE is allowing this certificate to be trusted.  Firefox and Safari are denying the certificate.  Any clues on what I need to do?  We are using the 2443 port, not the standard 443 port on a Linux machine.  We are on Ezproxy 5.3.  I am trying to implement the SSL for JSTOR secure access.  Any suggestions would be appreciated. 

 

Sincerely,

 

Edith List

 

_______________________

Edith Pfeifer List

Librarian, Associate Director

Marshall Brooks Library

Principia College

1 Maybeck Place

Elsah, IL 62028

Phone: 618.374.5076

Fax: 618.374.5107

email: edith.list <at> principia.edu

http://www.principiacollege.edu/library

_______________________

 

You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu

Peter Kovaleski | 1 Jul 2011 06:18
Favicon

Re: SSL Wildcard Certificates from ipsCA for JSTOR secure access

Edith,

Your issues are caused by IPSCA, they had a problem with their Trusted Root Certificate back in December of
2009.  They allowed it to expire and they have not worked with Firefox or Safari to trust their new root cert.  

We decided to go with GoDaddy. because their wildcard cert. was priced reasonably and it is trusted by all browsers.

Regards,


Peter Kovaleski
Network UNIX Administrator
Oral Roberts University
7777 S Lewis Ave
Tulsa, OK 74171
918-495-7092
918-645-1323 Cell


>>> Edith List <Edith.List <at> prin.edu> 6/30/2011 8:02 PM >>>

I received a wildcard certificate for our Ezproxy from IpsCa.  I and our IT staff have checked and double
checked that the certificate is correctly installed along with the intermediate certificatesl. 
However, only IE is allowing this certificate to be trusted.  Firefox and Safari are denying the
certificate.  Any clues on what I need to do?  We are using the 2443 port, not the standard 443 port on a Linux
machine.  We are on Ezproxy 5.3.  I am trying to implement the SSL for JSTOR secure access.  Any suggestions
would be appreciated.  
 
Sincerely,
 
Edith List
 
_______________________
Edith Pfeifer List
Librarian, Associate Director
Marshall Brooks Library
Principia College
1 Maybeck Place
Elsah, IL 62028
Phone: 618.374.5076
Fax: 618.374.5107
email: edith.list <at> principia.edu
http://www.principiacollege.edu/library

_______________________
 
You are currently subscribed to ezproxy as: pkovaleski <at> oru.edu. 
To unsubscribe, send request to scacad <at> itec.suny.edu
---
You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu
Maureen Olle-LaJoie | 1 Jul 2011 19:01
Favicon

RE:Wildcard Certificate Error

It looks like it was a chaining certificate.  Thanks for the insight!

 

Maureen

 

*******************************

Maureen Olle-LaJoie

Head of Library Technology and Circulation

University of Wisconsin-River Falls

River Falls, WI  54022

Phone: 715-425-3799

Fax: 715-425-0609

E-mail: maureen.olle-lajoie <at> uwrf.edu

 

From: Shannon E. Fox [mailto:sfox <at> austincollege.edu]
Sent: Friday, June 17, 2011 2:25 PM
To: EZProxy discussion list
Subject: RE:[ezproxy] Wildcard Certificate Error

 

Is the chaining certificate added? Missing the chaining cert was what was causing our errors.

 

Shannon Fox

Coordinator of Electronic Collections and Services

 

Austin College | Abell Library Center

900 N. Grand Ave Ste. 6L | Sherman, Texas 75090

903.813.2559 | sfox <at> austincollege.edu

 

 

From: Maureen Olle-LaJoie [mailto:maureen.olle-lajoie <at> uwrf.edu]
Sent: Friday, June 17, 2011 1:16 PM
To: EZProxy discussion list
Subject: [ezproxy] Wildcard Certificate Error

 

My institution renewed its SSL wildcard certificate and has been having some problems with error messages saying the site is untrusted.  Once we added the Option IgnoreWildcardCertificate to config.txt and restarted the proxy server, IE, Opera, Chrome, and ChromePlus started behaving normally again.  Firefox still gives an untrusted connection error for some reason.  I’d appreciate any advice on how to get this message to disappear.

 

Sincerely,
Maureen

 

*******************************

Maureen Olle-LaJoie

Head of Library Technology and Circulation

University of Wisconsin-River Falls

River Falls, WI  54022

Phone: 715-425-3799

Fax: 715-425-0609

E-mail: maureen.olle-lajoie <at> uwrf.edu

 

You are currently subscribed to ezproxy as: sfox <at> austincollege.edu.
To unsubscribe, send request to scacad <at> itec.suny.edu

You are currently subscribed to ezproxy as: maureen.olle-lajoie <at> uwrf.edu.
To unsubscribe, send request to scacad <at> itec.suny.edu

You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu

Shannon E. Fox | 1 Jul 2011 21:18
Favicon

RE:Wildcard Certificate Error

You’re very welcome, glad I could be of help. Happy 4th!

 

Shannon

 

From: Maureen Olle-LaJoie [mailto:maureen.olle-lajoie <at> uwrf.edu]
Sent: Friday, July 01, 2011 12:01 PM
To: EZProxy discussion list
Subject: RE:[ezproxy] Wildcard Certificate Error

 

It looks like it was a chaining certificate.  Thanks for the insight!

 

Maureen

 

*******************************

Maureen Olle-LaJoie

Head of Library Technology and Circulation

University of Wisconsin-River Falls

River Falls, WI  54022

Phone: 715-425-3799

Fax: 715-425-0609

E-mail: maureen.olle-lajoie <at> uwrf.edu

 

From: Shannon E. Fox [mailto:sfox <at> austincollege.edu]
Sent: Friday, June 17, 2011 2:25 PM
To: EZProxy discussion list
Subject: RE:[ezproxy] Wildcard Certificate Error

 

Is the chaining certificate added? Missing the chaining cert was what was causing our errors.

 

Shannon Fox

Coordinator of Electronic Collections and Services

 

Austin College | Abell Library Center

900 N. Grand Ave Ste. 6L | Sherman, Texas 75090

903.813.2559 | sfox <at> austincollege.edu

 

 

From: Maureen Olle-LaJoie [mailto:maureen.olle-lajoie <at> uwrf.edu]
Sent: Friday, June 17, 2011 1:16 PM
To: EZProxy discussion list
Subject: [ezproxy] Wildcard Certificate Error

 

My institution renewed its SSL wildcard certificate and has been having some problems with error messages saying the site is untrusted.  Once we added the Option IgnoreWildcardCertificate to config.txt and restarted the proxy server, IE, Opera, Chrome, and ChromePlus started behaving normally again.  Firefox still gives an untrusted connection error for some reason.  I’d appreciate any advice on how to get this message to disappear.

 

Sincerely,
Maureen

 

*******************************

Maureen Olle-LaJoie

Head of Library Technology and Circulation

University of Wisconsin-River Falls

River Falls, WI  54022

Phone: 715-425-3799

Fax: 715-425-0609

E-mail: maureen.olle-lajoie <at> uwrf.edu

 

You are currently subscribed to ezproxy as: sfox <at> austincollege.edu.
To unsubscribe, send request to scacad <at> itec.suny.edu

You are currently subscribed to ezproxy as: maureen.olle-lajoie <at> uwrf.edu.
To unsubscribe, send request to scacad <at> itec.suny.edu

You are currently subscribed to ezproxy as: sfox <at> austincollege.edu.
To unsubscribe, send request to scacad <at> itec.suny.edu

You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu

Flahaut Anne | 4 Jul 2011 10:57
Picon

Expert Review of Medical Devices

Hi,

Does anyone have a working stanza for this journal?

Expert Review of Medical Devices

Our EZProxy config is

T Expert Review of Medical Devices
U http://www.expert-reviews.com/loi/erd
DJ expert-reviews.com
HJ expert-reviews.com

and it seems not to be working off-campus
Thanks

Anne

--

-- 
Anne Flahaut Steiner
Responsable de la Bibliothèque numérique
Service commun de la documentation
Université Lille 2 Droit et Santé
1, Place de Verdun
59045 Lille cedex
Tél. +33(0)3 20 62 35 93
Fax +33(0)3 20 62 35 88
anne.flahaut <at> univ-lille2.fr

---
You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu

Hamparian,Don | 6 Jul 2011 00:20
Picon
Favicon

EZproxy - upcoming releases

Hello this is a summary of the issues we are resolving in the upcoming release, V5.4.1, which will be released within 2 weeks;  and issues which are being resolved in V5.5, slated for September. I am including our JIRA numbers for these issues to hopefully simplify how we refer to them. If you have questions, don’t reply to me directly as I will be on holiday but reply to ezproxy <at> oclc.org.

 

Thanks!

 

EZPROX-633

The string concatenation operator is interpreted as a character belonging to the neighboring textual constant rather than as a concatenation operator. This will be fixed in EZproxy V5.5. If you see this problem, the workaround is to insert a space around the operator. For example, this syntax UserFile("groups/" . login:instNumber.".txt") works, while UserFile("groups/".login:instNumber.".txt") does not.

 

EZPROX-609

In V5.4, the restart function did not correctly restart EZproxy on Windows platforms. This problem has been fixed in V5.4.1.

 

EZPROX-608

The IPC file (named ezproxy.ipc) isn't created on Windows platforms. This allowed multiple instances of Ezproxy to be started on a server out of the same directory. This problem has been fixed in V5.4.1.

 

EZPROX-611

The use of Shibboleth with groups resulted in the presentation of logup.htm instead of the completion of authentication. This problem has been fixed in V5.4.1.

 

EZPROX-626

EZproxy does not work Shibboleth IdP version 2.3. We understand what the issue is and are implementing a change to resolve this issue. This change will not be in V5.4.1. We anticipate fixing this problem in EZproxy V5.5, to be released in September.

 

EZPROX-613

The limit on number of includeFile entries was inadvertently set much smaller in V5.4. This problem has been fixed in V5.4.1. The limits set in V5.4.1 are 4096 include files allowed at a depth of up to 64 nested includes - include files with another include statement.

 

EZPROX-612

If EZproxy is restarted and an IPC file exists, EZproxy will now issue a message suggesting you can delete this file if you know EZproxy isn't currently running. Before this change, EZproxy would not start or issue a related message. This change is in V5.4.1.

 

EZPROX-627

Some sites are reporting Shibboleth authentication was not working with EZproxy V5.3 on the Solaris operating system. We are testing this scenario with V5.4.1. We do not believe this is a problem with V5.4.1.


EZPROX-632

When users authenticate using Shibboleth 1.3, each authentication results in the message: "SAMLResponse no encrypted Assertion elements" being written to the messages.txt file. This message can be ignored. We will resolve the spurious logging of this message in V5.5.

 

EZPROX-610

Message "SAML received assertion without a status of success, denying access" logged with a failure to authenticate with Shibboleth. This issue has existed since V5.1d and has been reported with institutions in the UK access federation. We are researching this issue and will either issue an update to EZproxy or describe a configuration method to resolve this problem as soon as we can test it.

 

 

Don Hamparian

Senior Product Manager

Web and Data Services

Identity Management & EZproxy

 

OCLC

mailto:hamparid <at> oclc.org

614.764.6017 (voice)

614.975.5750 (mobile)

IM, IP Phone (Skype) donhamp2

ICQ: 412-913-446

http://worldcat.org/devnet

 

You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu

Rich Wenger | 6 Jul 2011 00:46
Picon
Favicon

RE:EZproxy - upcoming releases

Don.

 

Thanks very much for this helpful information.  It is very useful to us.

 

Best,

Rich

 

From: Hamparian,Don [mailto:hamparid <at> oclc.org]
Sent: Tuesday, July 05, 2011 6:20 PM
To: EZProxy discussion list
Subject: [ezproxy] EZproxy - upcoming releases

 

Hello this is a summary of the issues we are resolving in the upcoming release, V5.4.1, which will be released within 2 weeks;  and issues which are being resolved in V5.5, slated for September. I am including our JIRA numbers for these issues to hopefully simplify how we refer to them. If you have questions, don’t reply to me directly as I will be on holiday but reply to ezproxy <at> oclc.org.

 

Thanks!

 

EZPROX-633

The string concatenation operator is interpreted as a character belonging to the neighboring textual constant rather than as a concatenation operator. This will be fixed in EZproxy V5.5. If you see this problem, the workaround is to insert a space around the operator. For example, this syntax UserFile("groups/" . login:instNumber.".txt") works, while UserFile("groups/".login:instNumber.".txt") does not.

 

EZPROX-609

In V5.4, the restart function did not correctly restart EZproxy on Windows platforms. This problem has been fixed in V5.4.1.

 

EZPROX-608

The IPC file (named ezproxy.ipc) isn't created on Windows platforms. This allowed multiple instances of Ezproxy to be started on a server out of the same directory. This problem has been fixed in V5.4.1.

 

EZPROX-611

The use of Shibboleth with groups resulted in the presentation of logup.htm instead of the completion of authentication. This problem has been fixed in V5.4.1.

 

EZPROX-626

EZproxy does not work Shibboleth IdP version 2.3. We understand what the issue is and are implementing a change to resolve this issue. This change will not be in V5.4.1. We anticipate fixing this problem in EZproxy V5.5, to be released in September.

 

EZPROX-613

The limit on number of includeFile entries was inadvertently set much smaller in V5.4. This problem has been fixed in V5.4.1. The limits set in V5.4.1 are 4096 include files allowed at a depth of up to 64 nested includes - include files with another include statement.

 

EZPROX-612

If EZproxy is restarted and an IPC file exists, EZproxy will now issue a message suggesting you can delete this file if you know EZproxy isn't currently running. Before this change, EZproxy would not start or issue a related message. This change is in V5.4.1.

 

EZPROX-627

Some sites are reporting Shibboleth authentication was not working with EZproxy V5.3 on the Solaris operating system. We are testing this scenario with V5.4.1. We do not believe this is a problem with V5.4.1.


EZPROX-632

When users authenticate using Shibboleth 1.3, each authentication results in the message: "SAMLResponse no encrypted Assertion elements" being written to the messages.txt file. This message can be ignored. We will resolve the spurious logging of this message in V5.5.

 

EZPROX-610

Message "SAML received assertion without a status of success, denying access" logged with a failure to authenticate with Shibboleth. This issue has existed since V5.1d and has been reported with institutions in the UK access federation. We are researching this issue and will either issue an update to EZproxy or describe a configuration method to resolve this problem as soon as we can test it.

 

 

Don Hamparian

Senior Product Manager

Web and Data Services

Identity Management & EZproxy

 

OCLC

mailto:hamparid <at> oclc.org

614.764.6017 (voice)

614.975.5750 (mobile)

IM, IP Phone (Skype) donhamp2

ICQ: 412-913-446

http://worldcat.org/devnet

 

You are currently subscribed to ezproxy as: rwenger <at> mit.edu.
To unsubscribe, send request to scacad <at> itec.suny.edu

You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu

Michael Waldman | 6 Jul 2011 00:50
Favicon

EZProxy and Mintel products

Hi everyone,

I am fairly new to EZProxy but have set up a few things successfully. However I have not been able to get Mintel
products to work. 

This is what I have:

URL from vendor: Mintel Oxygen:  http://www.academic.mintel.com
T Mintel Oxygen
U http://www.academic.mintel.com 
D www.academic.mintel.com

URL from vendor: Global Market Navigator (GMN): www.gmn.mintel.com

T Global Market Navigator 
U http://www.gmn.mintel.com
D www.gmn.mintel.com

On campus, both get to a page where users have to Accept the conditions of the vendor before getting to the
database proper.

Thanks!

Mike

Michael Waldman
Head, Collection Management
Associate Professor 
Baruch College Library
151 East 25th Street
New York, NY 10010
646-312-1689 (V) / 646-312-1691 (F)
Michael.Waldman <at> baruch.cuny.edu 

-----Original Message-----
From: Stephen Brown [mailto:brownsr <at> lrcm.usuhs.mil] 
Sent: Thursday, June 30, 2011 10:20 AM
To: EZProxy discussion list
Subject: [ezproxy] EZProxy and CAS

We are trying to integrate our EZProxy 5.3 server with our university's new CAS Single-Sign-On service.  We
are half-way there.

When our users log in to another CAS service (in this case , Sakai), and then follow a link to to our EZProxy
server, users are challenged A SECOND TIME to provide their CAS login credentials.  This works but isn't
the second login prompt redundant?

Any advice is appreciated from other CAS users.

 - Steve Brown

--
Stephen R. Brown, Contractor, HJF
Director, Applied Medical Informatics
Assistant Professor of Biomedical Informatics Uniformed Services University James A. Zimble Learning
Resource Center
4301 Jones Bridge Road
Bethesda, Maryland 20814-4799
Voice: 301-295-3358, Fax: 301-295-3795
Stephen.Brown.CTR <at> LRCM.USUHS.MIL

Classification:  UNCLASSIFIED 
Caveats: None

---
You are currently subscribed to ezproxy as: michael.waldman <at> baruch.cuny.edu.
To unsubscribe, send request to scacad <at> itec.suny.edu

---
You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu

Leslie Mathews | 6 Jul 2011 01:21
Favicon

Wiley Online Library


Hello,
Did Wiley change the proxy config for Wiley Online Library? Does anyone have a proxy config that is working
for this?
Thanks,
Leslie


Leslie Mathews
Acting Director, Library Services
Fielding Graduate University
2112 Santa Barbara Street, 
Santa Barbara, CA 93105

lmathews <at> fielding.edu 
(805) 690-4373
Fax: (805) 690-4313

View all archived Library WebEx sessions at 
http://libguides.fielding.edu/webex-archive




---
You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu
UC_EAccess | 6 Jul 2011 06:07
Picon
Picon
Favicon

Virtual Hosts - How are they created?

We recently had an issue with the "Max Virtual Hosts Error" with EZProxy, which was resolved by raising the
limit from 3000 to 5000. However a couple of days late IT allowed us access to the admin area, and under
server status / host maintenance, it states "Peak virtual hosts/limit: 1385/5000". Given that we only
have 1385 peak hosts and IT have assured me they have not removed any hosts, I am wondering why we had the
error with the 3000 hosts limit?

I would also like to ask a more general question, when are virtual hosts created? When the definition is
created or when the database is first accessed from the client end? It is my understanding that the virtual
host consists of the name and the port representing the Web domain and a set of proxy rule expressions
(defined in the database.cfg file), and allows mapping between the vendor database and the client. Is
this correct? OCLC seems to have precious little information about how EZProxy works at a more finite level.
---
You are currently subscribed to ezproxy as: gee-ezproxy2 <at> m.gmane.org.
To unsubscribe, send request to scacad <at> itec.suny.edu


Gmane