Zen Cart Logo

Ssl

Views: 228

Results 1 to 20 of 22
11 Apr 2012, 3:33 AM
#1
patriciawhipp avatar

patriciawhipp

New Zenner

Join Date:
Jan 2008
Posts:
8
Plugin Contributions:
0

Ssl

Contact button does not work. I have found no solution posted.
"Add to Cart" buttons do not work. I have found no solutions.
Changing the number in the cart on an item does not work.
When I try asking I get asked if I have bought a cup of coffee for you. The answer is YES.

11 Apr 2012, 4:17 AM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Ssl

Hard to help if you don't actually ask a question.

Please click Reply below and answer all the questions in the Posting Tips section on that page.

12 Apr 2012, 6:01 AM
#3
patriciawhipp avatar

patriciawhipp

New Zenner

Join Date:
Jan 2008
Posts:
8
Plugin Contributions:
0

Re: Ssl

Sorry that you don't understand. HOW do I make the "Add to Cart" button work on SSL?
HOW do I make the "Contact Us" button work on SSL?
How do I make changes in the quantity on the cart work on SSL?

Somehow, I felt that saying that so far I have found no solutions, makes the question redundant!

13 Apr 2012, 3:16 AM
#4
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Ssl

It's very unusual for someone to want those specific actions to happen over SSL. Please explain your business reason behind wanting SSL on things that don't normally involve anything that requires special security protection.

And, when you answer, please also answer all the questions shown in the Posting Tips section on the reply screen. To see that screen, click the "Reply" button below. (NOT the "quick reply" button).

17 Apr 2012, 3:01 AM
#5
patriciawhipp avatar

patriciawhipp

New Zenner

Join Date:
Jan 2008
Posts:
8
Plugin Contributions:
0

Re: Ssl

My website is SSL. Therefore everything is SSL. Not just a few parts of the website.

The "Add to Cart" button is a part of the store. Therefore it is SSL It does not work. What do I need to change to make it work?

The "Contact Us" button is a part of the store. Therefore it is SSL. It does not work. What do I need to change to make it work?

The cart is a part of the store. People often want to make a change in their cart, not just delete something. Therefore it is SSL. It does not work. What do I need to change to make it work?

If I need to change my shopping cart program, if you cannot help me with these problems, what Shopping Cart program would you suggest?

17 Apr 2012, 3:07 AM
#6
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Ssl

PatriciaWhipp:

My website is SSL.

...

everything is SSL. Not just a few parts of the website.

Why?

Most sites don't work like that.

It's normal to treat certain pages as SSL, only when needed, such as when sensitive information is being passed. There's no need to run all other pages over SSL at all ... quite pointless indeed.

17 Apr 2012, 11:23 AM
#7
schoolboy avatar

schoolboy

Totally Zenned

Join Date:
Jun 2005
Location:
Cumbria, UK
Posts:
10,327
Plugin Contributions:
0

Re: Ssl

The confusion may stem from the fact that the OP may not understand the purpose of SSL.

If you think that "SSL" secures your site, or reduces the risk of hacking, then you are mistaken.

SSL does TWO things:

  1. It encrypts sensitive data when that data is being transmitted over the internet.
  2. It provides a visitor to the site of evidence of a site's authenticity - ie: the site they are visiting is the site they are expecting to visit, and not some "spoof" site "pretending" to be some other site.

In the case of (1) above, the only time data is "sensitive" is when it involves personal information about, or from, the visitor, and ZC is quite clever in invoking SSL only when such data is ready to be transmitted.

17 Apr 2012, 1:33 PM
#8
fairestcape avatar

fairestcape

Totally Zenned

Join Date:
Mar 2008
Location:
Cape Town & London (depends on the season)
Posts:
2,957
Plugin Contributions:
0

Re: Ssl

PatriciaWhipp:

If I need to change my shopping cart program, if you cannot help me with these problems, what Shopping Cart program would you suggest?

It seems more alarming that you don't understand the protocols of how the internet works. Perhaps you should reconsider having a shopping cart at all.

There are NO "proper, sophisticated" shopping carts out there that would be so dumb as to force SSL across the site.

Firstly: It just isn't necessary. There is no logical reason to have full SSL on a site.

Secondly: It SLOWS A SITE DOWN and puts more load on servers, databases and other components.
**
Thirdly:** It may have a detrimental effect on how search engines spider and index your content, though there are some indications that most SE's can cope with SSL.
**
Finally:** It does not (as many people think) protect the site against hackers, crooks and other rogues looking to exploit it.

And why, yes, WHY would a group of highly experienced business-people and code developers (viz: the zencart dev team) build a system that was fundamentally flawed regarding SSL ?

17 Apr 2012, 1:59 PM
#9
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Ssl

schoolboy:

The confusion may stem from the fact that the OP may not understand the purpose of SSL.

If you think that "SSL" secures your site, or reduces the risk of hacking, then you are mistaken.

It has been many blue moons since I've seen anyone other than myself state this fact. I thought I was a voice in the wilderness :lookaroun

schoolboy:

SSL does TWO things:

Weelll... It used to do two things.

schoolboy:

  1. It encrypts sensitive data when that data is being transmitted over the internet.

Just to show I'm as pedantic as ever, it also encrypts NON sensitive data. :)

schoolboy:

  1. It provides a visitor to the site of evidence of a site's authenticity - ie: the site they are visiting is the site they are expecting to visit, and not some "spoof" site "pretending" to be some other site.

Once upon a time this was indeed the case. SSL certificates used to be expensive because those purchasing them had to provide evidence that they were who they said they were, and the Certificate issuers actually performed checks to verify the evidence provided was valid/genuine ... In other words, any site with an SSL certificate had been truly authenticated by an independent 3rd party.

Cert providers such as THAWTE still require this type of validation as far as I'm aware, and as such, they are still very expensive compared to (say) RapidSSL.

The cheap certificates are issued to anyone that has ten bucks to spend. No authentication required, which makes them totally useless for authentication purposes. Sadly, most people don't seem to be aware of this fact. It is actually a trivial matter for a 'bad guy' to purchase a certificate for (say) bankofamrerica.com and set up an an authentic looking site, complete with SSL... The 'hard' part for them is hijacking the users DNS to direct them to the bogus site rather than the real one (and even this isn't too difficult).
I wish I could say this is just a theoretical scenario, but alas, there are many documented cases where this exact thing has happened, and no doubt is still happening in some places.

I can appreciate that this is no news to you, and that some, (perhaps many) people think I'm scaremongering, but facts are facts, whether we like them or not.

I'd rather have people know about this weakness in SSL than have them assume that just because a site does have an SSL it is the real McCoy.

Cheers
Rod

17 Apr 2012, 2:11 PM
#10
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Ssl

fairestcape:

There are NO "proper, sophisticated" shopping carts out there that would be so dumb as to force SSL across the site.

You'd be surprised.

I was actually a wee bit disappointed with Zencart V1.5 when I noticed the admin configure file has in big bold text

"WE RECOMMEND THAT YOU USE SSL PROTECTION FOR YOUR ENTIRE ADMIN:"

OK, I can appreciate that this isn't the same as the entire zencart store, but nonetheless I don't see much point in encrypting the entire Admin either.

However, I also don't see it causing harm, so I am happy to accept that if this is what the team recommend I'm not going to be one to argue against their recommendations.

I may be vocal and opinionated, but I'm no fool. :) (well, not much of one) <grin>

Cheers
Rod

18 Apr 2012, 5:22 AM
#11
patriciawhipp avatar

patriciawhipp

New Zenner

Join Date:
Jan 2008
Posts:
8
Plugin Contributions:
0

Re: Ssl

I see no need to go into some of the questions, or comments. The host I am on provides SSL for the whole site, not for a few pages. Since I find stores I go to very frustrating when they keep jumping from SSL to regular, it suits me fine to have it totally SSL.

It has been an improvement, very definitely. However, from this post, and previous posts I see an attitude which causes me to wonder of you have any plans to help correct the problems which have been created.

I have used Zen Cart on another Host for 2 years, which was a horrible experience. I went to another site for 24 hours, then found GoDaddy. I am using v1.5.0 on GoDaddy .

The only changes I have done has been the admin change. I have used this version and host for several years before I went to SSL, and have only had minor problems. All of which I have found ways to work around. The steps I have taken since I went to SSL are not satisfactory. It looks very unprofessional.

18 Apr 2012, 6:53 AM
#12
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Ssl

While you assert that your assumption is that there is "an attitude which causes me to wonder of you have any plans to help correct the problems which have been created", I observe also that you have no intention of acknowledging that it seems you're the only one experiencing these problems.

That said, while Zen Cart was never designed to do as you are trying to make it do, I have tested the operation of running the entire store under SSL by setting the HTTP_SERVER to the appropriate https:// address, and found no problems when using it with original uncustomized core code without any addons. Tried it on four different hosting company server configurations.

As such it's very difficult to help you since the problem can't be consistently recreated. To come up with a proper "fix" for a legitimate "bug" requires an environment where the problems can be consistently triggered and therefore also inspected and analyzed, and solutions tested.

In that regard it suggests that the problem is localized to your site. Whether that's a combination of your addons or customizations or your hosting service or the phase of the moon, is hard to say. But it's compelling food for thought.

18 Apr 2012, 7:30 AM
#13
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Ssl

DrByte:

Whether that's a combination of your addons or customizations or your hosting service** or the phase of the moon**, is hard to say. But it's compelling food for thought.

Shock, horror! You should know better than making a tongue in cheek comment like that. Intended or not, some people will actually think you are serious and that phase of the moon can affect a computer.

LOL... just yanking ya chain :)

Cheers
Rod

18 Apr 2012, 8:03 AM
#14
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Ssl

PatriciaWhipp:

I see no need to go into some of the questions, or comments.

Opening yourself up to discussions and comments is a good way to learn stuff.

For example:

PatriciaWhipp:

The host I am on provides SSL for the whole site, not for a few pages.

Well, no it doesn't, because that is not the way SSL works. Any site, regardless of the host will be able to serve up SSL and Non-SSL pages with equal ease.

Unless you are open to comments you will be forever under a false impression (such as this) that is only ever going to make things more difficult for yourself.

PatriciaWhipp:

Since I find stores I go to very frustrating when they keep jumping from SSL to regular, it suits me fine to have it totally SSL.

On a correctly configured server the users are able to go back and forth between secure and non secure pages without even noticing (unless they've enabled a browser option that pops up an alert everytime they leave an SSL page), BUT the only people that enable this are those that are over paranoid and have no understanding as to what SSL actually does (other than it is a 'security thing').

I consider this kind of thing a bit like when people complain about having to click on the "Are you sure" button whenever they wish to delete a file, never realising that there are options and methods that can be set that will fix the thing they are complaining about. Or worse, they know about such options, choose not to use them, but still complain about the 'problem'.

It's absurd really, but I see it on an almost daily basis. :(
No, I am NOT trying to imply that you are one of these people, I am just stating a fact to make you aware that such people do exist.

PatriciaWhipp:

I see an attitude which causes me to wonder of you have any plans to help correct the problems which have been created.

This is a false perception. It is quite common when people read things they either don't understand, or simply don't like.

PatriciaWhipp:

I have used Zen Cart on another Host for 2 years, which was a horrible experience.

I know you will probably take this in a way that is not intended, but why on earth would you persist using a host for 2 years if it was such a horrible experience?

Cheers
Rod

18 Apr 2012, 9:15 AM
#15
vividknowledge avatar

vividknowledge

New Zenner

Join Date:
Apr 2012
Location:
Florida
Posts:
9
Plugin Contributions:
0

Re: Ssl

Out of morbid curiosity, I have to see this... could we ask the OP to provide a link to said phenomenon?
P.S Im glad to see i am not the only one who pulls all nighters. ;-)

18 Apr 2012, 5:41 PM
#16
schoolboy avatar

schoolboy

Totally Zenned

Join Date:
Jun 2005
Location:
Cumbria, UK
Posts:
10,327
Plugin Contributions:
0

Re: Ssl

I have a sneaking feeling that the OP is on an antiquated system requiring httpdocs and httpsdocs... And the host thinks symlinks is something you spray onto a rusty bicycle chain...

21 Apr 2012, 7:10 AM
#17
patriciawhipp avatar

patriciawhipp

New Zenner

Join Date:
Jan 2008
Posts:
8
Plugin Contributions:
0

Re: Ssl

My apologies! I talked with two different people (two different days) at GoDaddy. It turns out there is one button that had to be pushed, and all problems went away! I did not realize, or see, how that caused the situations you stated above. The first person at GoDaddy recommended it. The next day I spoke with another technician, found out more of what was going on, and by 1:00 pm this afternoon everything was fixed, and all my "warnings" were pulled out of the store.

21 Apr 2012, 9:57 AM
#18
schoolboy avatar

schoolboy

Totally Zenned

Join Date:
Jun 2005
Location:
Cumbria, UK
Posts:
10,327
Plugin Contributions:
0

Re: Ssl

So. like everybody else on GoDaddy, it would appear your problem IS GoDaddy... (I find it horrifying that so many people put their sites onto this awful host - and then blame the designers of the software (like ZC) when things go belly-up.)

Glad you got it sorted, but the best way to sort all issues relating to your site is to host elsewhere.

21 Apr 2012, 1:12 PM
#19
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Ssl

PatriciaWhipp:

It turns out there is one button that had to be pushed, and all problems went away!

For the benefit of others, would it be too much to ask what this 'button' was that needed to be pushed?

As you have probably noted, rightly or wrongly GoDaddy get a lot of bad press around these parts, but that doesn't prevent many of us from still trying to help people solve their issues, and it would help everyone if the solutions (or lack of) to any given problem is documented.

Let us for a moment assume that someone had came before you with the exact same problems went through the same (frustrating) steps that you did in order to find the solution, eventually to find out about this 'button'.

Now, let us assume that you came along, as you did, with the exact same issue, and our responses, based on the previous persons feedback was "Oh, yeah, this is an easy fix, it just needs one button to be pushed". How would you feel about such a response? Surely you'd want a bit more information than that? You could even be offended by thinking we are being deliberately unhelpful, even though that isn't the case.

Now, again, without trying to offend you, I'm going to wager that your next response isn't going to be helpful to anyone, but will be along the lines of "I don't know, the people at GoDaddy didn't tell me".

I would assume, that like us, you wouldn't want others to share the same experience at finding a resolution, so how about it? Can you provide any more information other than "one button had to be pushed"? I see a lot of GoDaddy users swear by how good GoDaddy support is, but sometimes I have to wonder if they don't intentionally cause a problem so that they can demonstrate how "good" they are in their ability to fix it, while us Zenners are still stuggling to put the peices together.
Yes, I can appreciate how cynical this may sound, but what else are we to think?

Ulimately it doesn't matter whether the issues are GoDaddy's or ZenCarts - It isn't a matter of placing blame, it is a matter of isolating the problems and sharing the solutions when they are found. Us Zenners tend to do both, but the GoDaddy compliants just go on and on, because even when the solutions are found, the information isn't shared, or, the information that is shared is next to useless, and this is, and always has been my issue with GoDaddy (and dare I say, many GoDaddy supporters).

Cheers
Rod

21 Apr 2012, 8:41 PM
#20
patriciawhipp avatar

patriciawhipp

New Zenner

Join Date:
Jan 2008
Posts:
8
Plugin Contributions:
0

Re: Ssl

The fix! Go to the page with the hosting menu's. Go to the "Content" menu. Under that menu go to the "URL Redirect" screen. If you have a "301 redirect", click the button to remove that. I believe that a year ago I was told I needed that. However, you do not want it. Already, in half a day, I have 5 times as many hits today as I have had this past year! Those redirects block search engines is what I was told yesterday.