gerardsweeney Posted October 30, 2018 Posted October 30, 2018 All.. Looking for a little assistance in terms of getting access to this site. https://scholar.hw.ac.uk Behind our Websense (or ForcePoint, as I think it's called now) proxy, users on IE or Chrome get: This site is not secure Error code DLG_FLAGS_INVALID_CA Users can click "Go onto the webpage", and they get access but with a Certificate error warning at the top. As a test, I took one of our DirectAccess laptops home and tried accessing the site. Using proxy, I got the same error. If I switched IE to direct (because I'm at home), then I got on. Once I was on, then I could access the site behind proxy. I'm guessing that our https filtering proxy is mangling or blocking some kind of https certificate for the user. Once it's in place, all is well. All feedback welcomed. Cheers, Gerard
LeMarchand Posted October 30, 2018 Posted October 30, 2018 OK here on Firefox, Edge, IE & Chrome. Different proxy, though! 1
bossman Posted October 30, 2018 Posted October 30, 2018 Smoothwall here using Chrome browser... No problem here....all secure so I guess its exactly that... 1
limawhiskey Posted October 30, 2018 Posted October 30, 2018 Looks like your proxy system doesn't like it as the site's HTTPS certificate chain is badly configured: https://www.sslshopper.com/ssl-checker.html#hostname=scholar.hw.ac.uk https://whatsmychaincert.com/?scholar.hw.ac.uk https://www.ssllabs.com/ssltest/analyze.html?d=scholar.hw.ac.uk&hideResults=on&latest Adding the intermediate CA cert (QuoVadis Global SSL ICA G2) to your proxy system should allow connections: https://www.quovadisglobal.com/QVRepository/DownloadRootsAndCRL.aspx 3
Arthur Posted October 30, 2018 Posted October 30, 2018 ^ What @limawhiskey said. I had to add the QuoVadis Global SSL ICA G2 intermediate certificate to our Sophos XG proxy last year after experiencing the same issue with a different website. Since getting the XG I have had to add around 27 intermediate and/or root certificates (five of which are from QuoVadis!). QuoVadis EV SSL ICA G3 QuoVadis Global SSL ICA G2 QuoVadis Root CA1 G3 QuoVadis Root CA2 G3 QuoVadis Root CA3 G3
gerardsweeney Posted October 31, 2018 Author Posted October 31, 2018 All. Thanks very much to all of you for taking the time to test and troubleshoot. Have a (virtual) chocolate biscuit each. I emailed Scholar's tech support page last night, and they've resolved the issue this morning. Much obliged! Gerard 1
limawhiskey Posted October 31, 2018 Posted October 31, 2018 No problem. Credit to the tech support folks at Scholar - they turned that around quickly. The Jisc certificate service uses QuoVadis so it might be worth adding all the intermediate certs anyway if you can. I checked our Smoothwall and they are included in the 'built-in' installed CA list. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now