Jump to content

Recommended Posts

Posted

All..

 

Looking for a little assistance in terms of getting access to this site.

 

https://scholar.hw.ac.uk

 

Behind our Websense (or ForcePoint, as I think it's called now) proxy, users on IE or Chrome get:

 

This site is not secure

Error code DLG_FLAGS_INVALID_CA

 

Users can click "Go onto the webpage", and they get access but with a Certificate error warning at the top.

 

 

As a test, I took one of our DirectAccess laptops home and tried accessing the site.

Using proxy, I got the same error.

 

If I switched IE to direct (because I'm at home), then I got on.

Once I was on, then I could access the site behind proxy.

 

I'm guessing that our https filtering proxy is mangling or blocking some kind of https certificate for the user. Once it's in place, all is well.

 

All feedback welcomed.

 

Cheers,

Gerard

Posted

Looks like your proxy system doesn't like it as the site's HTTPS certificate chain is badly configured:

 

 

Adding the intermediate CA cert (QuoVadis Global SSL ICA G2) to your proxy system should allow connections: https://www.quovadisglobal.com/QVRepository/DownloadRootsAndCRL.aspx

  • Thanks 3
Posted

^ What @limawhiskey said.

 

I had to add the QuoVadis Global SSL ICA G2 intermediate certificate to our Sophos XG proxy last year after experiencing the same issue with a different website.

 

Since getting the XG I have had to add around 27 intermediate and/or root certificates (five of which are from QuoVadis!). :(

 

QuoVadis EV SSL ICA G3
QuoVadis Global SSL ICA G2
QuoVadis Root CA1 G3
QuoVadis Root CA2 G3
QuoVadis Root CA3 G3

Posted

All.

 

Thanks very much to all of you for taking the time to test and troubleshoot.

Have a (virtual) chocolate biscuit each.

 

I emailed Scholar's tech support page last night, and they've resolved the issue this morning.

 

Much obliged!

Gerard

  • Thanks 1
Posted

No problem.

 

Credit to the tech support folks at Scholar - they turned that around quickly.

 

The Jisc certificate service uses QuoVadis so it might be worth adding all the intermediate certs anyway if you can. I checked our Smoothwall and they are included in the 'built-in' installed CA list.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...