Hi,

Unfortunately, the only way to run DSpace 7 via HTTP is via "localhost" 
URLs (which is similar to a development mode).   Otherwise, your user's 
browsers may accidentally block important Cookies (especially the XSRF 
token) from being sent back to the REST API, causing an inability to login 
(which is a 403 error). This is usually the result of a user's web-browser 
strictly *blocking* those Cookies, unless they are sent via HTTPS.  It's a 
security protection of modern web browsers.

So, we are not aware of anyway to get around this and run DSpace via HTTP 
in production.  It's much easier (and more secure) to buy an inexpensive 
SSL cert, or use a free service like Let's Encrypt: https://letsencrypt.org/

Tim


On Friday, February 25, 2022 at 6:51:12 AM UTC-6 [email protected] wrote:

> I have installed Dspace 7.2 and working fine from the localhost domain. 
> When I try in production I end up with a 403/forbidden error and actually, 
> the documentation says it has to be configured with HTTPS. I tried a 
> self-signed certificate, still I didn't get right. *Is there a 
> way/configuration that makes SSL/HTTPS requirements optional for intranet 
> use? *
> Your comment ...
>
> Thanks in advance.
>

-- 
All messages to this mailing list should adhere to the Code of Conduct: 
https://www.lyrasis.org/about/Pages/Code-of-Conduct.aspx
--- 
You received this message because you are subscribed to the Google Groups 
"DSpace Technical Support" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/dspace-tech/4c03df2d-f4ff-4fca-a856-2b7d652c7040n%40googlegroups.com.

Reply via email to