ssl with wingate proxy

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

ssl with wingate proxy

Postby pmartin » Jun 30 07 5:54 am

I would like to use wingate proxy configured in the IE to access a HTTPS that uses a SSL in the wingate log i get the site showing a SSL://my.site.ca:443 and then ssl://my.site.ca:-1 the site then carashes and i get a java error. The site has a java login form the controls access.

The site works if i use the wingate client on the computer but then the user needs to logon to wingate at boot up for the different internal components to work. I would prefer to not use the client or nat juse the proxy if possible.

I can give the site name if neccessary it is a public site.
Thanks
Pierre Martin
pmartin
 
Posts: 5
Joined: Jun 30 07 5:27 am

Re: ssl with wingate proxy

Postby Nev » Jul 01 07 10:55 pm

Hi Pierre,

To list the public site might be useful to look at this!
--
Nev.
Nev
WinGate Guru
 
Posts: 861
Joined: Sep 22 03 11:35 pm
Location: Mudgee ~ NSW ~ Australia

Postby pmartin » Jul 12 07 8:05 am

the public site is
my.homehardware.ca claims link
pmartin
 
Posts: 5
Joined: Jun 30 07 5:27 am

Postby jamesc » Jul 12 07 10:44 pm

I just navigated there and couldn't find the issue you are experiencing.

If Nev does not sort you out then the forum may need:

1. A procedure to replicate the problem – e.g. go to this link, then that one, then that etc...
2. What version of WinGate.
3. What authentication method.
4. Whether you tried a caching policy; a concept is shown below.
5. Do you have any plugins; e.g. KAV for WinGate / Puresight for WinGate.
6. When you try to use that Java control, are any Authentication Failures happening within the System Messages? GateKeeper --> View menu --> System Messages.
*You may also want to turn on debug logging in the WWW Proxy, replicate the error and then see what extra information is logged:
C:\Program Files\WinGate\Logs\WWW Proxy server\WWW Proxy Server.log


Image
The changes between version 6.x releases can be reviewed here:
http://www.wingate.com/showfaq.php?faqid=2

Skype: wingatejames
jamesc
Qbik Staff
 
Posts: 928
Joined: Apr 04 05 2:04 pm
Location: Auckland, New Zealand

Postby Nev » Jul 12 07 10:57 pm

Hi Pierre and James,

There is no apparent fault using SeaMonkey to browse the site here, or IE for that matter, except that it is slower [isn't it always!].

I have a feeling that it could be the browser and the JRE might need updating?

Shouldn't be the cache as SSL isn't stored / intercepted from memory.
--
Nev.
Nev
WinGate Guru
 
Posts: 861
Joined: Sep 22 03 11:35 pm
Location: Mudgee ~ NSW ~ Australia

Postby jamesc » Jul 12 07 11:10 pm

Thanks Nev,

I usually throw in a "try a caching policy" when websites are not displayed correctly - I have had a couple of support tickets in the past where the explanation of the clients issue would not make me think to advise making a caching policy, and then later down the track I find out that is how it is resolved.
The changes between version 6.x releases can be reviewed here:
http://www.wingate.com/showfaq.php?faqid=2

Skype: wingatejames
jamesc
Qbik Staff
 
Posts: 928
Joined: Apr 04 05 2:04 pm
Location: Auckland, New Zealand

Postby pmartin » Jul 21 07 7:03 am

Sorry for the delay in getting back to you about this.

wingate version 6.2.1 build1133

the error shows up once i click on the claims links

my.homehardware.ca/forms90/f90servlet?config=claims

Authentification I have tried with basic and java client. I have also tried with a assumed address.

I set up a cache policy a shown to Not "cache " containg
//my.homehardware.ca

I can't install WGIC or NAT I only want to use the Proxy

Also there is no plug ins installed

I have opend the java consol that the web site starts and here is the log:

(sorry it is in french)

JInitiator: Version 1.3.1.13
Utilisation de la version JRE 1.3.1.13-internal Java HotSpot(TM) Client VM
Répertoire d'accueil de l'utilisateur = C:\Documents and Settings\wrk110

Configuration du proxy : Configuration manuelle

Proxy : 10.24.42.200:80

Remplacement du proxy :

JAR cache enabled
Location: C:\Documents and Settings\wrk110\Oracle Jar Cache
Maximum size: 50 MB
Compression level: 0



----------------------------------------------------
c: clear console window
f: finalize objects on finalization queue
g: garbage collect
h: display this help message
l: dump classloader list
m: print memory usage
q: hide console
s: dump system properties
t: dump thread list
x: clear classloader cache
0-5: set trace level to <n>
----------------------------------------------------

java.io.IOException: Unexpected response 500 from proxy 10.24.42.200:80

WARNING: error reading my.homehardware.ca/forms90/java/f90all_jinit.jar from JAR cache.
Downloading //my.homehardware.ca/forms90/java/f90all_jinit.jar to JAR cache
[color=red]java.io.IOException: Unexpected response 500 from proxy 10.24.42.200:80[/color]
at oracle.jinitiator.protocol.https.HttpsClient.tunnelThroughProxy(Unknown Source)

java.util.zip.ZipException: Le fichier spécifié est introuvable


WARNING: Unable to cache my.homehardware.ca/forms90/java/f90all_jinit.jar
java.io.IOException: Unexpected response 500 from proxy 10.24.42.200:80


Thanks for you help
Pierre
pmartin
 
Posts: 5
Joined: Jun 30 07 5:27 am

Postby jamesc » Jul 26 07 11:09 pm

I will ask QA to investigate.
The changes between version 6.x releases can be reviewed here:
http://www.wingate.com/showfaq.php?faqid=2

Skype: wingatejames
jamesc
Qbik Staff
 
Posts: 928
Joined: Apr 04 05 2:04 pm
Location: Auckland, New Zealand

Postby pmartin » Jul 27 07 7:28 am

Thanks i will await information.

The end user likes the configuration options of wingate ( highly configurable) but is willing to go a hardware solution that will allow him to controller users internet sites (white list) as well as a password solution on each desktop to allow more access to authorized users. (whitout a reboot). but I must work with the SSL site.

Thanks
pmartin
 
Posts: 5
Joined: Jun 30 07 5:27 am

Postby jamesc » Aug 09 07 6:21 pm

QA was looking at this issue this afternoon, and when researching the version history of this Oracle AddOn it shows that there are some problems with its HTTPS configuration. QA downloaded the latest version from the Oracle site and installed it; they then ran out of time and will take this up again in the morning.
The changes between version 6.x releases can be reviewed here:
http://www.wingate.com/showfaq.php?faqid=2

Skype: wingatejames
jamesc
Qbik Staff
 
Posts: 928
Joined: Apr 04 05 2:04 pm
Location: Auckland, New Zealand

Postby pmartin » Aug 10 07 2:42 am

Thanks I will await more information
pmartin
 
Posts: 5
Joined: Jun 30 07 5:27 am

Postby jamesc » Aug 10 07 3:00 pm

There does not seem to be a solution for this problem without using a secondary connection method. Even if you update to the latest version of the Jinitiator it is the website that decides what version you should use - not the user.

QA has recommended that you:

1. Review: http://www.oracle.com/technology/softwa ... hanges.txt

2. Review:
http://en.wikipedia.org/wiki/Jinitiator

3. Contact the Web Administrator of that server and let them know your issue.
The changes between version 6.x releases can be reviewed here:
http://www.wingate.com/showfaq.php?faqid=2

Skype: wingatejames
jamesc
Qbik Staff
 
Posts: 928
Joined: Apr 04 05 2:04 pm
Location: Auckland, New Zealand


Return to WinGate

Who is online

Users browsing this forum: No registered users and 10 guests

cron