Zen Cart Logo
Forums / Installing on a Linux/Unix Server / Installation of this Module is Disabled Until Your Admin Is Configured for SSL

Installation of this Module is Disabled Until Your Admin Is Configured for SSL

Views: 4,626

Results 1 to 8 of 8
19 Sep 2012, 6:31 PM
#1
jtfindc avatar

jtfindc

New Zenner

Join Date:
Sep 2012
Posts:
2
Plugin Contributions:
0

Installation of this Module is Disabled Until Your Admin Is Configured for SSL

Installed 1.51. Upgraded from 1.39h.

Installation appeared to go well. Made it through dbase upgrade, etc., etc.

I'm getting the frequently mentioned "ALERT: For security reasons, Installation of this module is disabled until your Admin is configured for SSL." message on the FirstData API payment module.

After initially connecting using a secure, SSL, connection in the admin screen, all menu selections "drop" me out of secure, into a standard connection, including menu / navigation to payments module.

{admin}/includes/configure.php file appears to be set correctly:

> define('HTTP_SERVER', 'https://xxx.org');

define('HTTPS_SERVER', 'https://xxx.org');
define('HTTP_CATALOG_SERVER', 'http://xxx.org');
define('HTTPS_CATALOG_SERVER', 'https://xxx.org');
// Use secure webserver for catalog module and/or admin areas?
define('ENABLE_SSL_CATALOG', 'false');
define('ENABLE_SSL_ADMIN', 'true');

I set and unset write permission to ensure the file got uploaded. Downloaded back to make sure the changes took effect.

I tried removing the FirstData/Linkpoint module, as suggested in another thread. Cannot re-install because of this issue.

I tried forcing an SSL connection by rewriting the address, with an https://. Getting the same "For Security Reasons" message.

Suggestions?

Arrggh! :bangin:

19 Sep 2012, 6:49 PM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Installation of this Module is Disabled Until Your Admin Is Configured for SSL

jtfindc:

{admin}/includes/configure.php file appears to be set correctly:>

define('HTTP_SERVER', 'https://xxx.org');

define('HTTPS_SERVER', 'https://xxx.org');
define('HTTP_CATALOG_SERVER', 'http://xxx.org');
define('HTTPS_CATALOG_SERVER', 'https://xxx.org');
// Use secure webserver for catalog module and/or admin areas?
define('ENABLE_SSL_CATALOG', 'false');
define('ENABLE_SSL_ADMIN', 'true');


Yes, that would be correct (assuming your xxx.org references are indeed correct).
jtfindc:

After initially connecting using a secure, SSL, connection in the admin screen, all menu selections "drop" me out of secure, into a standard connectionThen that means your HTTPS_SERVER and ENABLE_SSL_ADMIN are correct, but your HTTP_SERVER is still not pointing to the https URL ... which is pretty much always a result of the file on the server not being uploaded/updated. Go back and check the actual file contents.

I was thinking that the only other possibility might be an .htaccess rewrite rule, but then that would have meant your admin login wouldn't have been over SSL, but since you said it was, then that means .htaccess rewrite rules are unrelated here. So it must be the configure.php file contents not being uploaded.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

19 Sep 2012, 7:12 PM
#3
jtfindc avatar

jtfindc

New Zenner

Join Date:
Sep 2012
Posts:
2
Plugin Contributions:
0

Re: Installation of this Module is Disabled Until Your Admin Is Configured for SSL

Thanks for the quick response.

Okay. In retrospect, substituting "xxx.org" for my actual domain, not great. I hadn't gone to that URL - or given it much thought.
And don't, by the way. It's pretty much what you'd expect.

That said - I've re-downloaded {admin}/includes/configure.php. Values check out as before.

/includes/configure.php reads, in relevant part, as follows:

> define('HTTP_SERVER', 'https://xyzzy.org'); (Also not the real domain.)

define('HTTPS_SERVER', 'https://xyzzy.org');
// Use secure webserver for checkout procedure?
define('ENABLE_SSL', 'true');

Cleared cache and cookies.

I looked at the .htaccess file in my {admin} folder. I'm no Apache guru, but I don't see anything that looks like it might force a rewrite to a secure connection. There's a block commented, "# The following makes adjustments to the SSL protocol for Internet Explorer browsers," but no general rule, s'far as I can tell.

In the generated page source, all of the links to other pages in the menus are to "http://", not "https://"

20 Sep 2012, 4:24 AM
#4
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Installation of this Module is Disabled Until Your Admin Is Configured for SSL

Two things:

  1. Your NON-ADMIN /includes/configure.php file should NOT have an https URL in your HTTP_SERVER setting, because your storefront shouldn't be https on all pages.
    But the ADMIN one does need to serve all content over SSL because your admin deals with sensitive data most of the time ... which is why the instructions only tell you to make HTTP_SERVER and HTTPS_SERVER be the same in the ADMIN configure.php file.

  2. If your /admin/includes/configure.php and /includes/configure.php files are actually correct, then you have something ELSE interfering, such as OTHER files on your server containing the same sets of define() statements but with wrong info. So that could be in your /admin/includes/local/configure.php or /includes/local/configure.php (those /local/configure.php files should NEVER be uploaded to your server), or perhaps elsewhere. Only you can locate those other files which are interfering with normal operation.
    A good file-comparison tool will show you what extra files are on your server. Something like WinMerge, etc. http://www.zen-cart.com/wiki/index.php/Troubleshoot_-_Diagnosing_Obscure_Issues

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

25 Jan 2013, 8:24 PM
#5
amyn avatar

amyn

New Zenner

Join Date:
Jan 2011
Posts:
20
Plugin Contributions:
0

Re: Installation of this Module is Disabled Until Your Admin Is Configured for SSL

Anyone who is having this same problem, as I was, I solved mine per Dr. Byte's recommendation clarification:

  1. Your NON-ADMIN /includes/configure.php file should NOT have an https URL in your HTTP_SERVER setting, because your storefront shouldn't be https on all pages.
    But the ADMIN one does need to serve all content over SSL because your admin deals with sensitive data most of the time ... which is why the instructions only tell you to make HTTP_SERVER and HTTPS_SERVER be the same in the ADMIN configure.php file.

My admin/includes/config.php HTTP_SERVER was set at http://... INSTEAD of the correct way: https://...

Amy

18 Jan 2014, 3:39 PM
#6
cammy2014 avatar

cammy2014

New Zenner

Join Date:
Jan 2014
Location:
New York
Posts:
1
Plugin Contributions:
0

Re: Installation of this Module is Disabled Until Your Admin Is Configured for SSL

includes/ configure.php as follows:
/ Define the webserver and path parameters
// HTTP_SERVER is your Main webserver: eg-http://www.you_shop.us
// HTTPS_SERVER is your Secure webserver: eg-https://www.you_shop.us
define('HTTP_SERVER', 'http://www.you_shop.us');
define('HTTPS_SERVER', 'https://www.you_shop.us');

// Use secure webserver for checkout procedure?
define('ENABLE_SSL', 'true');
But the problem is that the linkpoint Gateway still can't recognize the SSL.
Installation of this Module is Disabled Until Your Admin Is Configure
(We are presently using: v1.5.0)

18 Jan 2014, 3:55 PM
#7
lat9 avatar

lat9

Administrator

Join Date:
Sep 2009
Location:
Stuart, FL
Posts:
14,104
Plugin Contributions:
56

Re: Installation of this Module is Disabled Until Your Admin Is Configured for SSL

Cammy2014:

includes/ configure.php as follows:
/ Define the webserver and path parameters
// HTTP_SERVER is your Main webserver: eg-http://www.you_shop.us
// HTTPS_SERVER is your Secure webserver: eg-https://www.you_shop.us
define('HTTP_SERVER', 'http://www.you_shop.us');
define('HTTPS_SERVER', 'https://www.you_shop.us');

// Use secure webserver for checkout procedure?
define('ENABLE_SSL', 'true');
But the problem is that the linkpoint Gateway still can't recognize the SSL.
Installation of this Module is Disabled Until Your Admin Is Configure
(We are presently using: v1.5.0)
Your admin's configure.php (/YOUR_ADMIN/includes/configure.php) needs to be set as:

  // HTTP_SERVER is your Main webserver: eg-http://www.you_shop.us
  // HTTPS_SERVER is your Secure webserver: eg-https://www.you_shop.us
  define('HTTP_SERVER', 'https://www.you_shop.us');
  define('HTTPS_SERVER', 'https://www.you_shop.us');

Essentially, to run the admin in SSL both the HTTP_SERVER and the HTTPS_SERVER constants must be https:// URLs.

11 Dec 2014, 3:11 PM
#8
nipinuk avatar

nipinuk

Zen Follower

Join Date:
Oct 2005
Location:
Hampshire, UK
Posts:
96
Plugin Contributions:
0

Re: Installation of this Module is Disabled Until Your Admin Is Configured for SSL

lat9:

Your admin's configure.php (/YOUR_ADMIN/includes/configure.php) needs to be set as:

// HTTP_SERVER is your Main webserver: eg-http://www.you_shop.us
// HTTPS_SERVER is your Secure webserver: eg-https://www.you_shop.us
define('HTTP_SERVER', 'https://www.you_shop.us');
define('HTTPS_SERVER', 'https://www.you_shop.us');

> Essentially, to run the admin in SSL both the HTTP_SERVER and the HTTPS_SERVER constants must be https:// URLs.

Thank you so much! I have been trying to solve this for days and days! All I needed to do was to add an 's'!!

Works and I don't get the error now. Happy days!