Bad server certificate trying to get to the top-level https://shibboleth.net from AWS or a zscaler address
Paul Wilt
Paul.Wilt at Clarivate.com
Tue Mar 1 21:04:12 UTC 2022
Scott--thank you!
________________________________
From: Cantor, Scott <cantor.2 at osu.edu>
Sent: Tuesday, March 1, 2022 4:02 PM
To: Shib Users <users at shibboleth.net>
Cc: Paul Wilt <Paul.Wilt at Clarivate.com>
Subject: Re: Bad server certificate trying to get to the top-level https://shibboleth.net from AWS or a zscaler address
On 3/1/22, 3:56 PM, "Paul Wilt via users" <users at shibboleth.net> wrote:
> Whoever runs https://urldefense.com/v3/__http://www.shibboleth.net__;!!NknhfzgzgQ!mog2Ju37xwcZaJoM_ugt_sIlvELTRrajpDGP9NiT4rWjycIcTswPWGPuKcIoCrlxGfU$ seems to have fixed the certificates that caused my zscaler
> InternetSecurity system to bitterly complain when I would try to access the Shibboleth Consortium. Thanks to
> whoever made that change!!! Greatly appreciated.
Matthew Slowe took it back and got the right people to fix it.
My concern is that nothing "automated" should be accessing https://urldefense.com/v3/__http://www.shibboleth.net__;!!NknhfzgzgQ!mog2Ju37xwcZaJoM_ugt_sIlvELTRrajpDGP9NiT4rWjycIcTswPWGPuKcIoCrlxGfU$ . We do have redirects, but anything meant to be accessed by any tools should not be getting sent to that server, it should resolve on shibboleth.net alone. So there may be a missing redirect or somebody is doing something they really don't need to be.
-- Scott
Confidentiality note: This e-mail may contain confidential information from Clarivate. If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this e-mail is strictly prohibited. If you have received this e-mail in error, please delete this e-mail and notify the sender immediately.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220301/255679dd/attachment.htm>
More information about the users
mailing list