Page 1 of 2 12 LastLast
Results 1 to 10 of 13
  1. #1
    Join Date
    May 2006
    Posts
    8
    Plugin Contributions
    0

    Default To https or not https ?

    Hi
    I'm trying to set up zencart for the first time. Before I start can anyone help with the following.

    Do I have to have some secure web space (https) to use zencart or is it possible to use it with "normal" web space ?
    I'm setting up a small website for a local theatre group, hoping to sell some merchandise etc with the idea of using paypal to process transactions.
    I thought paypal would do this securely at their end so there would be no need to have secure web space on my site.
    Any thoughts appreciated

  2. #2
    Join Date
    Nov 2004
    Location
    Norfolk, United Kingdom
    Posts
    3,036
    Plugin Contributions
    2

    Default Re: To https or not https ?

    Full ssl certs are so cheap these days that there's really no excuse for not having a cert. Most hosting companies provide decent shared ssl certs as part of the package at no extra cost if you don't want to spend $20-30 on a full ssl cert.

    I would never do business with an online site that did not protect my account login details and account information with encryption.

    Vger

  3. #3
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: To https or not https ?

    If all you're doing to collect payment is using paypal, then you don't need protection for client CC information ... BUT you are still collecting customer name, address, phone, email, etc ...... and people-in-the-know will be appreciative of knowing that you are protecting their personal information with SSL encryption.

    Also, don't buy a 40-bit encryption certificate... those are obsolete nowadays. Go for 128-bit.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  4. #4
    Join Date
    Nov 2004
    Location
    Norfolk, United Kingdom
    Posts
    3,036
    Plugin Contributions
    2

    Default Re: To https or not https ?

    Also, don't buy a 40-bit encryption certificate
    I didn't know anybody was still selling them

    Vger
    Last edited by Vger; 2 Jun 2006 at 02:39 PM.

  5. #5
    Join Date
    May 2006
    Posts
    8
    Plugin Contributions
    0

    Default Re: To https or not https ?

    Thanks for the comments folks.

    I was just curious as to whether it was essential to have some secure web space for Zencart to work properly. From what you say it looks like you don't need to, so that's fine as I can muck about with zencart before I get down to selling anything.

  6. #6
    Join Date
    Dec 2005
    Location
    My Own Fluffy Place, Pangea
    Posts
    420
    Plugin Contributions
    0

    Default Re: To https or not https ?

    Quote Originally Posted by Vger
    I didn't know anybody was still selling them

    Vger
    They don't, the encryption strength is auto-negotiated between the Server and Browser. You usually get AES-256 bits with FireFox and an updated Apache. The certificate is only used as an encryption and decryption keys.
    Yeah! I'm small! I'm Fluffy! *Stick tongue out*

  7. #7
    Join Date
    May 2006
    Posts
    8
    Plugin Contributions
    0

    Default Re: To https or not https ?

    I've had alook around and came across www.prontossl.com
    They seem to offer very cheap deals. Has anyone heard of this company?

    Just one quick question. Not entirely sure how this ssl malarky works. If I was using e.g. paypal to process customer payments would I still need to have some actual secure webspace to go with an SSL certificate or would I just need a certificate on its own?

  8. #8
    Join Date
    Dec 2005
    Location
    My Own Fluffy Place, Pangea
    Posts
    420
    Plugin Contributions
    0

    Default Re: To https or not https ?

    The SSL certificate have encryption keys that allow your servers to set up a secure connection. Then all you have to do is use https instead of http and the server secure any normal URL for you through the use of your SSL certificate.

    Haven't heard of the company, but the prices are only ok, not too cheap, I've seen RapidSSL being offered for $15 USD before by other resellers, so 15 pounds is certainly reasonable. It look like their prices are in GBP instead of USD so it's like an 88% markup from what I've seen other resellers are selling those things for.
    Yeah! I'm small! I'm Fluffy! *Stick tongue out*

  9. #9
    Join Date
    Jun 2006
    Location
    Toronto,ON, Canada
    Posts
    15
    Plugin Contributions
    0

    Default Re: To https or not https ?

    I am looking into SSL right now myself.

    Would you have any recommendations on where to purchase?

  10. #10
    Join Date
    Dec 2005
    Location
    My Own Fluffy Place, Pangea
    Posts
    420
    Plugin Contributions
    0

    Default Re: To https or not https ?

    If you're small and going for something that'll do but don't need premium stuff then the picking point should be the seal, some of those like the Rapid SSL one doens't have an interactive verify seal. All they have is like an image file. Get something with a nice looking seal that you can click on if you're going to be presenting it to the customers.

    I usually just get them at Godaddy, got a few installed on my sites and a few client's web site. Smooth install on Plesk, can't say about cPanel. They give you a small flash seal with your site's URL and it's clickable.
    Yeah! I'm small! I'm Fluffy! *Stick tongue out*

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. HTTPS not working
    By Fancyfrills in forum Basic Configuration
    Replies: 20
    Last Post: 11 Aug 2012, 07:42 PM
  2. Replies: 4
    Last Post: 19 Feb 2009, 06:02 PM
  3. Cart not in HTTPS
    By waytoolate in forum Installing on a Linux/Unix Server
    Replies: 3
    Last Post: 23 Sep 2008, 07:14 PM
  4. Domain Name Mismatch (https:// vs https://www
    By johana.pat in forum General Questions
    Replies: 5
    Last Post: 27 Apr 2008, 04:42 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg