Using a Combination Proxy Server / PURL Server for Off-Campus Access to Restricted Databases: A Solution for the University of Iowa



Similar documents
Remote Access. A Service Guide for Colleges. An overview of the opt-in Remote Access service provided by Ontario College Library Service

Getting Started with One Search for Destiny

Shibboleth and Library Resources

Getting started with One Search for Destiny. Overview. Before you start. Enabling the One Search service

4 - TexShare and HARLiC CARDS ( Online Application Form) 5 REMOTE ACCESS TO DATABASES

Campus VPN. Version 1.0 September 22, 2008

Smart Telephone System

Configuring Outlook for Windows to use your Exchange

How to set up Outlook Anywhere on your home system

Using Microsoft Expression Web to Upload Your Site

Hallpass Instructions for Connecting to Mac with a Mac

Scan to Quick Setup Guide

Using Microsoft Windows Authentication for Microsoft SQL Server Connections in Data Archive

Requirements Collax Security Gateway Collax Business Server or Collax Platform Server including Collax SSL VPN module

CONFIGURING AND USING WEBDAV IN LENOVO EMC LIFELINE

Please return this document to when complete.

(this is being worked on)

Using Internet or Windows Explorer to Upload Your Site

Portal Administration. Administrator Guide

Entrust Managed Services PKI. Getting an end-user Entrust certificate using Entrust Authority Administration Services. Document issue: 2.

The Einstein Depot server

Creating a generic user-password application profile

The University of Texas Rio Grande Valley. Network Security. Create a Virtual Private. Network (VPN) Connection. Network Security How-to:

Student Mail Access. Introduction. Option One: Using an Client

Application Note VAST Network settings

INTEGRATION GUIDE. DIGIPASS Authentication for VMware Horizon Workspace

How To Set Up Hopkins Wireless On Windows 7 On A Pc Or Mac Or Ipad (For A Laptop) On A Network Card (For Windows 7) On Your Computer Or Ipa (For Mac Or Mac) On An Ipa Or

BusinessObjects Enterprise XI Release 2

Dragonframe License Manager User Guide Version 1.2.2

MY HELPDESK - END-USER CONSOLE...

HallPass Instructions for Connecting to your Campus PC Using the ipad

User Management Tool 1.5

My Stuff Everywhere Your Content On Any Screen

Connecting to the University Wireless Network

Service Provider Interface Study

VPN clients configuration for Windows 98SE - for Library access

Phone: Fax: Box: 230

How We Use Your Personal Information On An Afinion International Ab And Afion International And Afinion Afion Afion

Configuring an IPsec VPN to provide ios devices with secure, remote access to the network

Orthopaedics SharePoint Site: User Guide. Version: Page 1 of 19

USING THE DNS/DHCP ADMINISTRATIVE INTERFACE Last Updated:

Teleworking Technology Guide and Checklist. UW Information Technology. November 2012

How to Set Up SSL VPN for Off Campus Access to UC eresources

Cisco Unity Voice Mail-

Authentication Methods

Click-To-Talk. ZyXEL IP PBX License IP PBX LOGIN DETAILS. Edition 1, 07/2009. LAN IP: WAN IP:

How To Install A Cisco Vpn Client V4.9.9 On A Mac Or Ipad (For A University)

How do I Install and Configure MS Remote Desktop for the Haas Terminal Server on my Mac?

Note: This documentation was written using the Samsung Galaxy S5 and Android version 5.0. Configuration may be slightly different.

Integration Guide. Duo Security Authentication

Installing the Microsoft Network Driver Interface

Copyright: WhosOnLocation Limited

DEPLOYMENT GUIDE DEPLOYING THE BIG-IP LTM SYSTEM WITH MICROSOFT WINDOWS SERVER 2008 TERMINAL SERVICES

nexvortex Setup Guide

Creating an FTP Server. using. FlashNAS ZFS

Network Security Policy

Configuration Manual

Information Technology Department. Miller School of Medicine New User Guide

Getting Started. Confirm that the Wi-Fi settings on your mobile terminal are enabled. Download Canon Mobile Printing and install it.

MultiSite Manager. Setup Guide

Accessing TP SSL VPN

Configuring an External Domain

How To Authenticate With Ezproxy On A University Campus (For A Non Profit)

Adobe Marketing Cloud Bloodhound for Mac 3.0

Paladin Computers Privacy Policy Last Updated on April 26, 2006

MaaS360 Mobile Enterprise Gateway

RingCentral Office. Configure Aastra phones with RingCentral

CA Unified Infrastructure Management Server

MaaS360 Mobile Enterprise Gateway

Phone Manager Application Support OCTOBER 2014 DOCUMENT RELEASE 4.1 SAGE CRM

Internet Telephony PBX System

Cloudera Manager Training: Hands-On Exercises

Net2 Anywhere - Installation

VERALAB LDAP Configuration Guide

How to use wired (Wireless) Phone to make off-net calls via Gateway

Quickstart guide to Configuring WebTitan

IPOne Phone System User Interface Guide

Web Authentication Application Note


THE OPEN UNIVERSITY OF TANZANIA

PowerLink for Blackboard Vista and Campus Edition Install Guide

VPN: Virtual Private Network Setup Instructions

Optional VBP-E at the Headquarters Location

Computer Science and Engineering MacOS Cisco VPN Client Installation and Setup Guide

Remote Desktop access via Faculty Terminal Server Using Internet Explorer (versions 5.x-7.x)

Iowa Student Loan Online Privacy Statement

PREPLY PRIVACY POLICY

Copyright

Outlook Profile Setup Guide Exchange 2010 Quick Start and Detailed Instructions

Transcription:

University of Iowa Libraries Staff Publications 4-29-1999 Using a Combination Proxy Server / PURL Server for Off-Campus Access to Restricted Databases: A Solution for the University of Iowa Paul A. Soderdahl University of Iowa Copyright 1999 Paul Soderdahl Hosted by Iowa Research Online. For more information please contact: lib-ir@uiowa.edu.

Using a Combination Proxy Server / PURL Server for Off-Campus Access to Restricted Databases: A Solution for the University of Iowa Paul A. Soderdahl University of Iowa Libraries Like many college and university libraries across the country, the University of Iowa Libraries continues to purchase more and more licenses for web-based resources, most of which are mounted remotely on the publishers' web servers. Though there are many ways for publishers to restrict access to their licensed databases, most have settled on one of four standard means for authentication. Some publishers issue a single institutional name and password which is required for accessing the site, presumably with the expectation that, somehow, the library will "discreetly" disseminate this single name and password to its potentially 30,000-person user base. Other publishers insist on issuing an individual name and password for each library patron who is authorized to access the site, or use some combination of unique name and password and institutional name and password. This is both an administrative nightmare and a potential violation of the American Library Association's Code of Ethics which protects "each library user's right to privacy and confidentiality." Rarely, but occasionally, publishers entrust the library to institute its own means of authentication. Most of the time, however, publishers simply request a list of valid IP addresses or IP subdomains for authorized access, a solution which is often the easiest for them to implement. While IP-based authorization generally provides convenient on-campus access to licensed databases, the problem occurs with off-campus faculty and students trying to access a restricted database through a commercial Internet Service Provider (ISP). Many libraries, including the University of Iowa, have implemented a proxy server to address this need. Faculty and students dialing in from off-campus configure their web browsers to use the library's proxy server. When an end user tries to access a remote IPrestricted database, the user is first prompted to authenticate with the proxy server. After authentication, the end user's request for a web page is sent to the proxy server and the proxy server issues the request to the remote resource. Since the proxy server is physically on the campus network, it carries an authorized IP address. Thus, the library assumes the responsibility for authenticating who is and who is not authorized to use the proxy server. At the University of Iowa, this authentication is tied to the library's patron database. From a technical standpoint, the solution works, and most institutions stop at this point. The problem arises, however, in marketing the proxy server so that faculty and students are aware of its existence and learn how to configure their web browsers to use it. The University of Iowa Libraries has taken an extra step with a PURL (persistent URL) server.

At the time a license for an IP-restricted database is signed, the database is cataloged, the proxy configuration file is updated, and a PURL address is created for the resource. This PURL address, then, is used in all links provided by the library and in any publicity for faculty and students. Using a PURL address has many advantages, including the ability to update an address in just one location if a URL changes, as well as the ability to gather some usage data on remote resources by logging hits on the PURL server. As far as the proxy server is concerned, however, the PURL server provides a unique way to self-market the proxy server and provide instructions to faculty and staff on configuring their web browsers to use the proxy server at the point of need. Specifically, the PURL server checks to see if the user has a campus IP address. If so, the user is instantly redirected to the remote resource. If not, the PURL server returns a set of instructions on how users can configure their browsers to access the proxy server and then links to the remote database when the configuration is complete. This solution has enabled thousands of University of Iowa students and faculty to learn about the proxy server with little direct marketing on the part of the library, and users are given the instructions at the point of need just in time. This presentation will discuss the technical aspects of how the proxy and PURL servers work together and describe the workflow in place to maintain the data on both.

University of Iowa Libraries Libraries-Wide Information System Proxy/PURL Server Configuration On campus > Off campus / UI affiliated; proxy server set up and already authenticated > Off campus / UI affiliated; proxy server set up but not yet authenticated this session Off campus / Not UI >Off campus/ UI affiliated; proxy not configured on client s end ps 7/22/98

University of Iowa Libraries Libraries-Wide Information System Proxy/PURL Server Configuration On campus Off campus / UI affiliated; proxy server set up and already authenticated Off campus / UI affiliated; proxy server set up but not yet authenticated this session Off campus / Not UI Off campus / UI affiliated; proxy not configured on client s end ps 7/22/98