Jump to content

Recommended Posts

Posted

Assistant head has been trying to get some resources from TES, but the resources search page doesn't render properly. Oddly, it works fine if he tries it on his iPad, and if I try it from my user. But from his account (and our test staff account) it doesn't work.

 

Primarily, it's not being blocked by Smoothwall, which was our first port of call. So I thought maybe security settings (we can edit ours, staff is set by policy). Both Security settings and the Advanced settings are identical (with the exception of Do-Not-Track)

 

Kind of at a loss here of where to go.

 

Untitled.png

Top: How it appears for Staff

Bottom: How it appears for me (and on his iPad)

Posted (edited)

Yes. But that happens to all users, so I don't see how that would make it affect him but not me.

All their other pages load fine (including searching other categories) and those too are https.

 

Edit: No, TES is not being decrypted. It's in our allow list so the traffic isn't inspected.

Edited by Garacesh
Posted

There are a few background requests to cloudfront.net and amazonaws.com, which serve the stylesheets.

Have a look through your Smoothie's logs for these to make sure something isn't going wrong with them.

Also, is your Smoothie up to date? There have been a few fixes for some HTTPS sites recently. I don't think they're related to this but it's something else to rule out.

Posted (edited)

Cloudfront is also unblocked, not sure about amazonaws.. I'll have to check.

Smoothwall logs are showing nothing but 200's. Everything 'looks' fine, nothing is showing as being blocked.

Not sure.. What is the latest version? :D A few low-prio updates but nothing that appears huge.

 

Edit: Update 87 is one of the low-prio ones. Scheduled it to update overnight.

Edited by Garacesh
Posted
Try it from Firefox and install the Firebug plugin. The "Net" tab of firebug shows all the web requests that are made, so you can see if any of them failed. In theory it should show you the same stuff as the Smoothwall log, but you never know so it's worth double checking. :)
Posted (edited)

Well using FireBug (handy! Will keep that one for further use) everything is either *.tes.co.uk or *.cloudfront.net which are both unblocked.. With the exception of one query to each of the following:

 

https://secure-uk.imrworldwide.com/gibberish and https://tsleducation.112.2o7.net/gibberish which are both giving me untrusted connection if I try and navigate to them 'normally' (Specifically: The certificate is not trusted because no issuer chain was provided. (Error code: sec_error_unknown_issuer))

Edited by Garacesh
Posted

The certificate chain on both of those looks fine to me:

 

Certificate chain

0 s:/serialNumber=8zNjMBehFD3Tbe0sezmihZ-h-hfwCArp/OU=GT17759042/OU=See http://www.rapidssl.com/resources/cps ©13/O

U=Domain Control Validated - RapidSSL®/CN=*.imrworldwide.com

i:/C=US/O=GeoTrust, Inc./CN=RapidSSL CA

1 s:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA

i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority

2 s:/C=US/O=GeoTrust, Inc./CN=RapidSSL CA

i:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA

 

and:

 

Certificate chain

0 s:/C=US/ST=California/L=San Jose/O=Adobe Systems Incorporated/OU=Adobe Marketing Cloud/CN=*.112.2o7.net

i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance CA-3

1 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance CA-3

i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA

 

My guess would be that your Smoothwall doesn't think the certificate chain is valid when it does its HTTPS interception - maybe its root certificates are out of date - I assume all other https sites work fine without the browser showing certificate warnings?

 

imrworldwide.com is registered to The Nielsen Company (no idea who they are), 2o7.net appears to be owned by Adobe. I guess you could try whitelisting those so they don't get decrypted by the Smoothwall.

Posted
We had the same problem with pintrest on staff group, but worked on admin, check your updates if any on you SW box, after our LA helpdesk mentioned there was an update missing, he installed it and all is fine.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...