<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
zscaler is a VPN-like utility that strongly verifies that the SSL certificates match the domain which is being protected.  </div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thus, it reports "<span style="font-family:Arial, sans-serif;text-align:left;background-color:rgb(255, 255, 255);display:inline !important">Access denied due to bad server certificate".  When I turn off that protection it allows me in.</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-family:Arial, sans-serif;text-align:left;background-color:rgb(255, 255, 255);display:inline !important"><br>
</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
====</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I think that the curl error (expired certificate) may be one of the mirrorlist servers.  I don't know how to communicate that to the maintainers of the mirrorlist.</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Thursday, February 24, 2022 5:56 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Paul Wilt <Paul.Wilt@Clarivate.com><br>
<b>Subject:</b> Re: Bad server certificate trying to get to the top-level https://shibboleth.net from AWS or a zscaler address</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">>    14: curl#60 - "SSL certificate problem: certificate has expired"<br>
<br>
The chain we're serving up is fine so far as I know (and I just checked it with openssl, the exact set we're returning are all unexpired). You can verify that for yourself.<br>
<br>
>    Or when running with zscaler we get the following error:<br>
<br>
The root of the vhost redirects to <a href="https://urldefense.com/v3/__http://www.shibboleth.net__;!!NknhfzgzgQ!nnGxDK7P4pPBoCTV_uP6_F6Wcfa-Rv-xRa-qHziH4cne5QpjqCaPTA-b_NBEdoO7i-w$">
https://urldefense.com/v3/__http://www.shibboleth.net__;!!NknhfzgzgQ!nnGxDK7P4pPBoCTV_uP6_F6Wcfa-Rv-xRa-qHziH4cne5QpjqCaPTA-b_NBEdoO7i-w$</a> , there are only specific content directories on the server that don't. I have no idea what zscaler is but it's irrelevant.<br>
<br>
-- Scott<br>
 <br>
<br>
</div>
</span></font></div>
<div>
<p style="font-size:8pt; line-height:8pt; font-family: 'Calibri',serif; color:#696969">
Confidentiality note: This e-mail may contain confidential information from Clarivate. If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this e-mail is strictly prohibited. If you have received
 this e-mail in error, please delete this e-mail and notify the sender immediately.
</p>
</div>
</body>
</html>