HSTS and EZproxy

Symptom

 

Applies to
Resolution

HSTS is not supported by EZproxy. EZproxy works with vendors who have the right to keep their sites secure or unsecured. The URL and the HJ lines in the stanzas can be HTTP or HTTPS. Forcing traffic as HTTPS through a proxy can create issues as EZproxy is already handling the HTTP-HTTPS translations. Self-hosted sites have the liberty to enable HSTS on their EZproxy domain and when they do that they get error messages on all the HTTP websites. We can offer the following solutions to those sites:

  1. Check for the HSTS header present in the EZproxy domain (https://gf.dev/hsts-test). Ask them to remove the "includeSubDomains" option from the Strict-Transport-Security header. That way, the EZproxy domain would be allowed to continue using HTTP.
  2. Ask the user to change all the links to HTTPS (they have to change these links everywhere including WC Discovery, the online library page, and config.txt)
  3. There are some resources like Brepolis that will not support HTTPS. In that case, a line like this might help to fix the issue:
    ProxyHostnameEdit apps.brepolis.net$ apps.brepolis.net

    Refer to: https://help.oclc.org/Library_Management/EZproxy/Configure_resources/ProxyHostnameEdit for more information.
Page ID
47246