Garacesh Posted February 9, 2015 Posted February 9, 2015 Assistant head has been trying to get some resources from TES, but the resources search page doesn't render properly. Oddly, it works fine if he tries it on his iPad, and if I try it from my user. But from his account (and our test staff account) it doesn't work. Primarily, it's not being blocked by Smoothwall, which was our first port of call. So I thought maybe security settings (we can edit ours, staff is set by policy). Both Security settings and the Advanced settings are identical (with the exception of Do-Not-Track) Kind of at a loss here of where to go. Top: How it appears for Staff Bottom: How it appears for me (and on his iPad)
OB1 Posted February 10, 2015 Posted February 10, 2015 Tes.co.uk is secure. Are you decrypting and inspecting it?
Garacesh Posted February 12, 2015 Author Posted February 12, 2015 (edited) Yes. But that happens to all users, so I don't see how that would make it affect him but not me. All their other pages load fine (including searching other categories) and those too are https. Edit: No, TES is not being decrypted. It's in our allow list so the traffic isn't inspected. Edited February 12, 2015 by Garacesh
OB1 Posted February 12, 2015 Posted February 12, 2015 There are a few background requests to cloudfront.net and amazonaws.com, which serve the stylesheets. Have a look through your Smoothie's logs for these to make sure something isn't going wrong with them. Also, is your Smoothie up to date? There have been a few fixes for some HTTPS sites recently. I don't think they're related to this but it's something else to rule out.
Garacesh Posted February 12, 2015 Author Posted February 12, 2015 (edited) Cloudfront is also unblocked, not sure about amazonaws.. I'll have to check. Smoothwall logs are showing nothing but 200's. Everything 'looks' fine, nothing is showing as being blocked. Not sure.. What is the latest version? A few low-prio updates but nothing that appears huge. Edit: Update 87 is one of the low-prio ones. Scheduled it to update overnight. Edited February 12, 2015 by Garacesh
Opendium_Steve Posted February 16, 2015 Posted February 16, 2015 Try it from Firefox and install the Firebug plugin. The "Net" tab of firebug shows all the web requests that are made, so you can see if any of them failed. In theory it should show you the same stuff as the Smoothwall log, but you never know so it's worth double checking.
Garacesh Posted February 16, 2015 Author Posted February 16, 2015 (edited) Well using FireBug (handy! Will keep that one for further use) everything is either *.tes.co.uk or *.cloudfront.net which are both unblocked.. With the exception of one query to each of the following: https://secure-uk.imrworldwide.com/gibberish and https://tsleducation.112.2o7.net/gibberish which are both giving me untrusted connection if I try and navigate to them 'normally' (Specifically: The certificate is not trusted because no issuer chain was provided. (Error code: sec_error_unknown_issuer)) Edited February 16, 2015 by Garacesh
Opendium_Steve Posted February 16, 2015 Posted February 16, 2015 The certificate chain on both of those looks fine to me: Certificate chain 0 s:/serialNumber=8zNjMBehFD3Tbe0sezmihZ-h-hfwCArp/OU=GT17759042/OU=See http://www.rapidssl.com/resources/cps ©13/O U=Domain Control Validated - RapidSSL®/CN=*.imrworldwide.com i:/C=US/O=GeoTrust, Inc./CN=RapidSSL CA 1 s:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority 2 s:/C=US/O=GeoTrust, Inc./CN=RapidSSL CA i:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA and: Certificate chain 0 s:/C=US/ST=California/L=San Jose/O=Adobe Systems Incorporated/OU=Adobe Marketing Cloud/CN=*.112.2o7.net i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance CA-3 1 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance CA-3 i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA My guess would be that your Smoothwall doesn't think the certificate chain is valid when it does its HTTPS interception - maybe its root certificates are out of date - I assume all other https sites work fine without the browser showing certificate warnings? imrworldwide.com is registered to The Nielsen Company (no idea who they are), 2o7.net appears to be owned by Adobe. I guess you could try whitelisting those so they don't get decrypted by the Smoothwall.
Mullaney18 Posted February 16, 2015 Posted February 16, 2015 We had the same problem with pintrest on staff group, but worked on admin, check your updates if any on you SW box, after our LA helpdesk mentioned there was an update missing, he installed it and all is fine.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now