Results 1 to 5 of 5
  1. #1
    Join Date
    Oct 2006
    Location
    Worcester, MA
    Posts
    453
    Plugin Contributions
    0

    Default SSL warning in admin after upgrade to 1.5.4

    Hello,

    I successfully (almost) upgraded a client's zencart from 1.5.3 to 1.5.4 over the weekend. All appeared fine but we are seeing the warning:

    ALERT: For security reasons, Editing of this module is disabled until your Admin is configured for SSL.
    in payment modules.

    I know that usually this would indicate that "ENABLE_SSL_ADMIN" was set to false or that "HTTPS_SERVER" or "HTTPS_CATALOG_SERVER" was incorrectly set. I have checked that these values are all correct in admin/includes/config.

    I did notice that the client's SSL certificate has a yellow triangle instead of the green padlock and that the cert is using older encryption (SH1). Would that kind of thing cause the alert to show in admin>payment modules?

    I have already let the client know that they should work with their hosting company to address the SSL issue I'm seeing but I was curious whether this will "fix" the issue in zen cart or whether the two things are coincidental.

    Thoughts? (and thanks!)
    Ellie Armsby

  2. #2
    Join Date
    Oct 2006
    Location
    Worcester, MA
    Posts
    453
    Plugin Contributions
    0

    Default Re: SSL warning in admin after upgrade to 1.5.4

    I should add that the SSL cert has not changed since prior to the upgrade to v1.5.4 and that this error was not showing prior to v1.5.4 (was on 1.5.3 before) So I was wondering whether something in the latest version detects a problem with the SSL cert and throws the alert to prevent a security problem.
    Ellie Armsby

  3. #3
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: SSL warning in admin after upgrade to 1.5.4

    It's simple (and explained in the configure.php file):

    For the Admin, to make the entire Admin operate in SSL, change the HTTP_SERVER define from http://yoursite.com to https://yoursite.com.
    Yes, that's defining HTTP_SERVER with an https URL.
    Just for the admin file.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  4. #4
    Join Date
    Oct 2006
    Location
    Worcester, MA
    Posts
    453
    Plugin Contributions
    0

    Default Re: SSL warning in admin after upgrade to 1.5.4

    Thanks Dr. Byte. I will change that and see if that solves it. I think I knew that somewhere but forgot! :)
    Ellie Armsby

  5. #5
    Join Date
    Oct 2006
    Location
    Worcester, MA
    Posts
    453
    Plugin Contributions
    0

    Default Re: SSL warning in admin after upgrade to 1.5.4

    Yup. That was it. Still reccomending the client update their SSL cert though. :)
    Ellie Armsby

 

 

Similar Threads

  1. v138a PHP Warning: htmlspecialchars() (after enabling SSL)
    By gbdriver in forum General Questions
    Replies: 0
    Last Post: 1 Feb 2012, 05:38 PM
  2. Warning after upgrade - configure.php is writable
    By LyndaRay in forum Upgrading from 1.3.x to 1.3.9
    Replies: 11
    Last Post: 14 Apr 2011, 03:58 PM
  3. Warning after upgrade
    By LyndaRay in forum Upgrading from 1.3.x to 1.3.9
    Replies: 3
    Last Post: 4 Sep 2009, 08:03 AM
  4. Warning after upgrade to Upgraded to Zen Cart 1.3.8a
    By karmasherbs in forum Upgrading from 1.3.x to 1.3.9
    Replies: 2
    Last Post: 27 Mar 2009, 04:16 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR