Results 1 to 10 of 13

Hybrid View

  1. #1
    Join Date
    May 2006
    Posts
    8
    Plugin Contributions
    0

    Default To https or not https ?

    Hi
    I'm trying to set up zencart for the first time. Before I start can anyone help with the following.

    Do I have to have some secure web space (https) to use zencart or is it possible to use it with "normal" web space ?
    I'm setting up a small website for a local theatre group, hoping to sell some merchandise etc with the idea of using paypal to process transactions.
    I thought paypal would do this securely at their end so there would be no need to have secure web space on my site.
    Any thoughts appreciated

  2. #2
    Join Date
    Nov 2004
    Location
    Norfolk, United Kingdom
    Posts
    3,036
    Plugin Contributions
    2

    Default Re: To https or not https ?

    Full ssl certs are so cheap these days that there's really no excuse for not having a cert. Most hosting companies provide decent shared ssl certs as part of the package at no extra cost if you don't want to spend $20-30 on a full ssl cert.

    I would never do business with an online site that did not protect my account login details and account information with encryption.

    Vger

  3. #3
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: To https or not https ?

    If all you're doing to collect payment is using paypal, then you don't need protection for client CC information ... BUT you are still collecting customer name, address, phone, email, etc ...... and people-in-the-know will be appreciative of knowing that you are protecting their personal information with SSL encryption.

    Also, don't buy a 40-bit encryption certificate... those are obsolete nowadays. Go for 128-bit.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  4. #4
    Join Date
    Nov 2004
    Location
    Norfolk, United Kingdom
    Posts
    3,036
    Plugin Contributions
    2

    Default Re: To https or not https ?

    Also, don't buy a 40-bit encryption certificate
    I didn't know anybody was still selling them

    Vger
    Last edited by Vger; 2 Jun 2006 at 02:39 PM.

  5. #5
    Join Date
    May 2006
    Posts
    8
    Plugin Contributions
    0

    Default Re: To https or not https ?

    Thanks for the comments folks.

    I was just curious as to whether it was essential to have some secure web space for Zencart to work properly. From what you say it looks like you don't need to, so that's fine as I can muck about with zencart before I get down to selling anything.

  6. #6
    Join Date
    Dec 2005
    Location
    My Own Fluffy Place, Pangea
    Posts
    420
    Plugin Contributions
    0

    Default Re: To https or not https ?

    Quote Originally Posted by Vger
    I didn't know anybody was still selling them

    Vger
    They don't, the encryption strength is auto-negotiated between the Server and Browser. You usually get AES-256 bits with FireFox and an updated Apache. The certificate is only used as an encryption and decryption keys.
    Yeah! I'm small! I'm Fluffy! *Stick tongue out*

  7. #7
    Join Date
    May 2006
    Posts
    8
    Plugin Contributions
    0

    Default Re: To https or not https ?

    I've had alook around and came across www.prontossl.com
    They seem to offer very cheap deals. Has anyone heard of this company?

    Just one quick question. Not entirely sure how this ssl malarky works. If I was using e.g. paypal to process customer payments would I still need to have some actual secure webspace to go with an SSL certificate or would I just need a certificate on its own?

 

 

Similar Threads

  1. HTTPS not working
    By Fancyfrills in forum Basic Configuration
    Replies: 20
    Last Post: 11 Aug 2012, 07:42 PM
  2. Replies: 4
    Last Post: 19 Feb 2009, 06:02 PM
  3. Cart not in HTTPS
    By waytoolate in forum Installing on a Linux/Unix Server
    Replies: 3
    Last Post: 23 Sep 2008, 07:14 PM
  4. Domain Name Mismatch (https:// vs https://www
    By johana.pat in forum General Questions
    Replies: 5
    Last Post: 27 Apr 2008, 04:42 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg