Author Topic: ssl and domain name  (Read 13142 times)

Offline epanagio

  • Newbie
  • *
  • Posts: 24
  • Karma: +2/-0
    • View Profile
ssl and domain name
« on: June 11, 2012, 05:20:28 PM »
The domain name is

randrbuyandsell dot com

we have a valid ssl installed. In System->Settings->Store URL we have https:// randrbuyandsell dot com/

In System->Settings->System we have SSL turned on. Save the settings and log off.

To be sure we clear the cache and then enter the URL randrbuyandsell dot com in chrome. I assumed that it will redirect it to https:// randrbuyandsell dot com but it doesn't.
Am I doing something wrong?

Offline abantecart

  • Administrator
  • Hero Member
  • *****
  • Posts: 4358
  • Karma: +298/-10
    • View Profile
    • Ideal Open Source Ecommerce Solution
Re: ssl and domain name
« Reply #1 on: June 11, 2012, 10:54:13 PM »
Where did you check SSL? I see it is working on your site.

Site stitch to SSL automatically when you login or go to registration. Only customer section and checkout pages are using SSL, not all product or catalog pages.

If you need whole site to use SSL all the time, you can can configure main URL in configuration to use HTTPS.
Please  rate your experience or leave your review
We need your help to build better free open source ecommerce platform for everyone. See how you can help

Offline epanagio

  • Newbie
  • *
  • Posts: 24
  • Karma: +2/-0
    • View Profile
Re: ssl and domain name
« Reply #2 on: June 12, 2012, 11:35:21 AM »
Because it didn't work I entered a redirect in apache. If you would like to test it I can remove the redirect for you to see.

"If you need whole site to use SSL all the time, you can can configure main URL in configuration to use HTTPS. " Is this the "Store URL:" ? I had it set to "https://randrbuyandsell.com/" and that didn't work either.

Let me know if you would like me to remove the redirect.

Thanks, Evan

Offline abantecart

  • Administrator
  • Hero Member
  • *****
  • Posts: 4358
  • Karma: +298/-10
    • View Profile
    • Ideal Open Source Ecommerce Solution
Re: ssl and domain name
« Reply #3 on: June 12, 2012, 12:29:27 PM »
I just tested this on my install and setting for SSL ON does work correctly.

Please remove the redirect and have setting for SSL ON in the admin -> settings.
Please  rate your experience or leave your review
We need your help to build better free open source ecommerce platform for everyone. See how you can help

Offline epanagio

  • Newbie
  • *
  • Posts: 24
  • Karma: +2/-0
    • View Profile
Re: ssl and domain name
« Reply #4 on: June 16, 2012, 10:03:01 PM »
Yes. You are correct. It does work correctly. I didn't understand that the ssl takes over only in certain areas. I thought that the whole entire site would have been under ssl.
THANKS!

Offline Nimitz1061

  • Full Member
  • ***
  • Posts: 190
  • Karma: +22/-0
  • No matter where you go, there you are...
    • View Profile
Re: ssl and domain name
« Reply #5 on: June 26, 2012, 09:06:34 PM »
The recommended approach to using SSL is that once the visitor enters a secure state, they do not leave it unless they leave the site, or log out.

The cart would benefit from a change to this approach.

David

Offline abantecart

  • Administrator
  • Hero Member
  • *****
  • Posts: 4358
  • Karma: +298/-10
    • View Profile
    • Ideal Open Source Ecommerce Solution
Re: ssl and domain name
« Reply #6 on: June 27, 2012, 08:50:31 AM »
Thank you for suggestion. We will note this.

There is a concern that regular catalog pages might have NON-SSL inclusions and this will cause warnings to poup if you have SSL enabled for these pages.
Please  rate your experience or leave your review
We need your help to build better free open source ecommerce platform for everyone. See how you can help

Offline Nimitz1061

  • Full Member
  • ***
  • Posts: 190
  • Karma: +22/-0
  • No matter where you go, there you are...
    • View Profile
Re: ssl and domain name
« Reply #7 on: June 29, 2012, 12:03:58 PM »
That is quite a reasonable concern.

Another concern that should be considered with ecommerce sites is that floating back and forth from secure to insecure states can increase opportunities to hijack the session. 

Its not reasonable to use content sourced from insecure servers or connections in any case.  In the end, the associated risks of viral loading, phishing and other code insertion should be sufficient to push the industry into a fully secure mode.  I will agree however that a good deal of thought should be applied before changing the application to meet this standard..

David

Offline abantecart

  • Administrator
  • Hero Member
  • *****
  • Posts: 4358
  • Karma: +298/-10
    • View Profile
    • Ideal Open Source Ecommerce Solution
Re: ssl and domain name
« Reply #8 on: June 29, 2012, 04:23:50 PM »
Excellent point about security. We will give it more thinking.
Please  rate your experience or leave your review
We need your help to build better free open source ecommerce platform for everyone. See how you can help

Offline swilkins

  • Newbie
  • *
  • Posts: 2
  • Karma: +0/-0
    • View Profile
Re: ssl and domain name
« Reply #9 on: August 10, 2016, 01:29:29 PM »
I have my SSL turned on and i am ready to enter my credit card information but I still do not get https in my url.  Help.  My site is live and unsecure.

Offline Basara

  • Administrator
  • Hero Member
  • *****
  • Posts: 5774
  • Karma: +274/-2
    • View Profile
Re: ssl and domain name
« Reply #10 on: August 11, 2016, 05:26:37 AM »
Hello.
You need to turn ON SSL in your AbanteCart settings
http://docs.abantecart.com/pages/settings/details.html

 

Powered by SMFPacks Social Login Mod