Page 1 of 2 12 LastLast
Results 1 to 10 of 17
  1. #1
    Join Date
    Feb 2006
    Posts
    326
    Plugin Contributions
    0

    Default Admin SSL not working??

    I just enabled (I thought) Admin SSL by changing to the following in the configure.php file in the admin directory:
    define('ENABLE_SSL_ADMIN', 'true');

    Now, when I go to the admin login page, I get https, and when I login the initial page is https. But as soon as I click on any other link within admin, it reverts to http.

    Did I miss anything?
    Thank you in advance!
    Give us your best shot!
    http://www.photoimprints.com

  2. #2
    Join Date
    Aug 2004
    Posts
    1,590
    Plugin Contributions
    1

    Default Re: Admin SSL not working??

    That is a normal procedure. A long time ago, I reported this behavior myself on the old forum. Zen-Cart uses switches between HTTP and HTTPS protocol - depending on which pages it is required to be SSL, or not, during your sessions activities (as this goes the same over the store-front).

  3. #3
    Join Date
    Feb 2006
    Posts
    326
    Plugin Contributions
    0

    Default Re: Admin SSL not working??

    Well... I sure wish that when I'm viewing a customers order with CC and all that info it was on https. It's not doing that.
    Thanks
    Give us your best shot!
    http://www.photoimprints.com

  4. #4
    Join Date
    Aug 2004
    Posts
    1,590
    Plugin Contributions
    1

    Default Re: Admin SSL not working??


    Well... I sure wish that when I'm viewing a customers order with CC and all that info it was on https. It's not doing that.
    Your point of vue is quite understandable. However, as long as you're working under the admin section, the DEV team assured the safety of the administration's navigation end. Each actions you are applying, (without mentionning any MODs that might be involved but simply from the core - speaking), there's nothing to be concerned about.

    Of course, bugs are constantly reported between each releases of Zen-Cart (over the 'Bug reports' section of the forum) as it also helps concerned users who thinks that Zen-Cart operates differently as it should operate normally.

    Meaning, in case you might encounter errornous with Zen-Cart and, might think it's a bug, you can always report these activities over that section so that the DEV team could try to reproduce the error and confirm if it's really a bug or not to you.

  5. #5
    Join Date
    Mar 2005
    Posts
    18
    Plugin Contributions
    0

    Default Re: Admin SSL not working??

    Quote Originally Posted by styledata
    Well... I sure wish that when I'm viewing a customers order with CC and all that info it was on https. It's not doing that.
    Thanks

    I am having the same concern as I have this very issue. When you are in the admin section it should be secured and when your not on https pages you are not secured - correct?

    Is there a way to secure the whole site to use only https?

  6. #6
    Join Date
    Aug 2004
    Posts
    1,590
    Plugin Contributions
    1

    Default Re: Admin SSL not working??


    I am having the same concern as I have this very issue. When you are in the admin section it should be secured and when your not on https pages you are not secured - correct?
    Not entirely correct. As long as your ZenID is involved in your URL, your sessions activities are encrypted. Sure, it does help when you're under the SSL protocol to view your page as it makes a harder job for hackers to hunt your admin account(s) down. Althought, you must realize that it uses more server ressources to maintain all pages under SSL. Which is why, switches has been placed by the DEV team.


    Is there a way to secure the whole site to use only https?
    Which brings the answer to a no.

    1 - More server ressources as, even, most pages doesn't require to be under SSL. From that point, it would become useless.

    2 - If option 1 were useful and that the DEV team releases a new version of Zen-Cart, you'd still need to redo the switching manually again from the cores. It is unlikely you'd like to redo the same steps all over again.

  7. #7
    Join Date
    Sep 2003
    Location
    Ohio
    Posts
    69,402
    Plugin Contributions
    6

    Default Re: Admin SSL not working??

    1 set both settings to be your secure site for the admin

    2 don't collect all CC info, use the split email address
    You are asking for trouble if you store all the info in the database and this is against the rules for credit cards

    Besides, when you get hacked do you really want the liability?
    Linda McGrath
    If you have to think ... you haven't been zenned ...

    Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!

    Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today: v1.5.5]
    Officially PayPal-Certified! Just click here

    Try our Zen Cart Recommended Services - Hosting, Payment and more ...
    Signup for our Announcements Forums to stay up to date on important changes and updates!

  8. #8
    Join Date
    Feb 2006
    Posts
    326
    Plugin Contributions
    0

    Default Re: Admin SSL not working??

    Quote Originally Posted by Ajeh
    1 set both settings to be your secure site for the admin
    What is the other setting besides the configure.php file in the admin/includes folder?
    Thank you
    Give us your best shot!
    http://www.photoimprints.com

  9. #9
    Join Date
    Aug 2004
    Posts
    1,590
    Plugin Contributions
    1

    Default Re: Admin SSL not working??

    There are no other direct settings except, of course, under the admin section in order to write into your SQL server for any modified settings.

  10. #10
    Join Date
    Feb 2006
    Posts
    326
    Plugin Contributions
    0

    Default Re: Admin SSL not working??

    Quote Originally Posted by TheOracle
    There are no other direct settings except, of course, under the admin section in order to write into your SQL server for any modified settings.
    I'm not sure what you just said :)
    Ajeh makes reference to two settings, I know about configure.php in the admin/includes folder, I'm wondering what the other one is.
    Give us your best shot!
    http://www.photoimprints.com

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. v139h admin site not working after SSL install
    By Kathi_S in forum General Questions
    Replies: 9
    Last Post: 7 Mar 2012, 06:17 PM
  2. Admin SSL not working!
    By helpme in forum Basic Configuration
    Replies: 1
    Last Post: 27 Aug 2007, 03:58 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR