Zen Cart Logo
Forums / General Questions / Make entire site SSL Only

Make entire site SSL Only

Views: 7,769

Results 1 to 20 of 26
30 Jan 2015, 6:40 PM
#1
jrich523 avatar

jrich523

New Zenner

Join Date:
Jan 2015
Location:
United States
Posts:
3
Plugin Contributions:
0

Make entire site SSL Only

Hey guys,

Was wondering what the best way was to force the site to be SSL only. I found some stuff on doing it via the .htaccess redirector, which will be fine, but i figure there is/should be a way via the config to do this as well?

Thanks
Justin

30 Jan 2015, 7:20 PM
#3
jrich523 avatar

jrich523

New Zenner

Join Date:
Jan 2015
Location:
United States
Posts:
3
Plugin Contributions:
0

Re: Make entire site SSL Only

Thanks for the response. From what I see here this is how to enable it, there is nothing here that would force SSL, or does enabling it also force SSL?

basically I can create a redirect fine, but i'd have to have two hits for every request the user makes forcing the redirect.

I see that there are a couple of methods that call/generate URLs and there is an SSL option on those methods, but, I dont want to have to review all the code to find where pages are referenced and if they request SSL or not. Was wondering if there was a setting to basically force SSL url generation in all cases

30 Jan 2015, 7:28 PM
#4
lhungil avatar

lhungil

Totally Zenned

Join Date:
Feb 2012
Location:
mostly harmless
Posts:
1,818
Plugin Contributions:
4

Re: Make entire site SSL Only

jrich523:

Thanks for the response. From what I see here this is how to enable it, there is nothing here that would force SSL, or does enabling it also force SSL?

basically I can create a redirect fine, but i'd have to have two hits for every request the user makes forcing the redirect. ...
Zen Cart always adds the contents of "HTTP_SERVER" or "HTTPS_SERVER" to the start of URLs. So if these are both configured as "https://www.example.com" the URLs will always point to the the "https://" version of the site.

In this case there are no redirects as the second click (and all subsequent clicks) by a visitor will always bring them to the HTTPS version of the page. If one adds a separate redirect in a server configuration (or per directory .htaccess file) to enforce HTTPS, you one get one redirect per time the client MANUALLY types into the URL "http://" or comes to your site from a link containing "http://".

NOTE: Unless there is a compelling reason to force HTTPS for all pages, there is a performance hit related to the use of HTTPS - which can impact ranking on search engines.

30 Jan 2015, 7:33 PM
#5
jrich523 avatar

jrich523

New Zenner

Join Date:
Jan 2015
Location:
United States
Posts:
3
Plugin Contributions:
0

Re: Make entire site SSL Only

ahh good idea, i'll give that a try.

Im heading towards the all SSL since google change their page rank a little and there is an overall push to get all pages SSL (regardless of the use)

https://www.eff.org/HTTPS-EVERYWHERE

figured since im dealing with CCs and the such anyways, might as well just do my part :)

Thanks!

15 Sep 2015, 5:53 PM
#6
tbohannon avatar

tbohannon

New Zenner

Join Date:
Jan 2011
Posts:
9
Plugin Contributions:
0

Re: Make entire site SSL Only

https://www.bodhisattva-store.com/listings/
ZC 1.5.0
Hosting on GoDaddy VPS
Dedicated SHA-2 SSL certificate to: https://www.bodhisattva-store.com managed through GoDaddy

Added Forced SSL rules in .htaccess file...these are the only rules in the .htaccess file:
#Force SSL on entire site
RewriteEngine On
RewriteBase /
#RewriteCond %{ENV:HTTPS} !on [NC]
RewriteCond %{SERVER_PORT} 80
RewriteRule ^(.*)$ https://bodhisattva-store.com/$1 [R,L]

I have enabled SSL as directed in the post below:

https://www.zen-cart.com/content.php?56-how-do-i-enable-ssl-after-i-have-installed-zen-cart multiple times.

Made changes in Store folder listings/includes/configure.php

// Define the webserver and path parameters
// HTTP_SERVER is your Main webserver: eg-http://www.your_domain.com
// HTTPS_SERVER is your Secure webserver: eg-https://www.your_domain.com
define('HTTP_SERVER', 'http://www.bodhisattva-store.com');
define('HTTPS_SERVER', 'https://www.bodhisattva-store.com');

// Use secure webserver for checkout procedure?
define('ENABLE_SSL', 'true');

// NOTE: be sure to leave the trailing '/' at the end of these lines if you make changes!
// * DIR_WS_* = Webserver directories (virtual/URL)
// these paths are relative to top of your webspace ... (ie: under the public_html or httpdocs folder)
define('DIR_WS_CATALOG', '/listings/');
define('DIR_WS_HTTPS_CATALOG', '/listings/');

Made changes in Admin folder:
/listings/taras_workspace/includes/configure.php

/**

  • WE RECOMMEND THAT YOU USE SSL PROTECTION FOR YOUR ENTIRE ADMIN:
  • To do that, make sure you use a "https:" URL for BOTH the HTTP_SERVER and HTTPS_SERVER entries:
    */
    define('HTTP_SERVER', 'http://www.bodhisattva-store.com');
    define('HTTPS_SERVER', 'https://www.bodhisattva-store.com');
    define('HTTP_CATALOG_SERVER', 'http://www.bodhisattva-store.com');
    define('HTTPS_CATALOG_SERVER', 'https://www.bodhisattva-store.com');

// secure webserver for admin? Valid choices are 'true' or 'false' (including quotes).
define('ENABLE_SSL_ADMIN', 'true');

// secure webserver for storefront? Valid choices are 'true' or 'false' (including quotes).
define('ENABLE_SSL_CATALOG', 'true');

// NOTE: be sure to leave the trailing '/' at the end of these lines if you make changes!
// * DIR_WS_* = Webserver directories (virtual/URL)
// these paths are relative to top of your webspace ... (ie: under the public_html or httpdocs folder)
$t1 = parse_url(HTTP_SERVER);$p1 = $t1['path'];$t2 = parse_url(HTTPS_SERVER);$p2 = $t2['path'];

define('DIR_WS_ADMIN', preg_replace('#^' . str_replace('-', '-', $p1) . '#', '', dirname($_SERVER['SCRIPT_NAME'])) . '/');
define('DIR_WS_CATALOG', '/listings/');
define('DIR_WS_HTTPS_ADMIN', preg_replace('#^' . str_replace('-', '-', $p2) . '#', '', dirname($_SERVER['SCRIPT_NAME'])) . '/');
define('DIR_WS_HTTPS_CATALOG', '/listings/');

== What's Working ===

Site browses in full HTTPS:

In Chrome site is fully HTTPS

In Firefox site is fully HTTPS

== Issues ==

Issue 1: In Firefox ONLY site browses with no errors until you click an Add To Cart button.
A browser security warning is displayed that it will be sent over insecure connection.

Issue 2: In all browsers, when I browse to admin folder I can login, but when I attempt to access features
or make edits login screen appears and edits are not saved.

Completely frustrated after spending hours on this!

15 Sep 2015, 6:28 PM
#7
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: Make entire site SSL Only

Wherever you see http: in the includes/configure.php or admin/includes/configure.php they need to read https:

If you are trying to have https on all pages from the point of being on any page... Also, for others reading this page, take a look at includes/functions/html_output.php the function zen_href_link provides more than just a check of the port for identification of SSL or not as not all methods use/identify to port 80.

There are also a few pages I think I recall (in ZC 1.5.4) that do not set the link type in the zen_href_link call to $request_type which when left off or not set to 'SSL' will result in a http: related link.

15 Sep 2015, 8:51 PM
#8
tbohannon avatar

tbohannon

New Zenner

Join Date:
Jan 2011
Posts:
9
Plugin Contributions:
0

Re: Make entire site SSL Only

As I posted I have all my http references pointing to the http URL and all https references point to the https URL.

So what am I missing here, other than poking around in the ncludes/functions/html_output.php you mentioned?

Thanks for responding!

15 Sep 2015, 8:59 PM
#9
tbohannon avatar

tbohannon

New Zenner

Join Date:
Jan 2011
Posts:
9
Plugin Contributions:
0

Re: Make entire site SSL Only

Looking at /includes/functions/html_output.php

I see the following entries (snippets copied from the file) regarding SSL...from what I can tell anything SSL is set to 'true' which means
it should be enabled right?

function zen_href_link($page = '', $parameters = '', $connection = 'NONSSL', $add_session_id = true, $search_engine_safe = true, $static = false, $use_dir_ws_catalog = true) {

if ($connection == 'NONSSL') {
$link = HTTP_SERVER;
} elseif ($connection == 'SSL') {
if (ENABLE_SSL == 'true') {
$link = HTTPS_SERVER ;
} else {
$link = HTTP_SERVER;

if ($use_dir_ws_catalog) {
if ($connection == 'SSL' && ENABLE_SSL == 'true') {
$link .= DIR_WS_HTTPS_CATALOG;
} else {
$link .= DIR_WS_CATALOG;
}
}

while ( (substr($link, -1) == '&') || (substr($link, -1) == '?') ) $link = substr($link, 0, -1);
// Add the session ID when moving from different HTTP and HTTPS servers, or when SID is defined
if ( ($add_session_id == true) && ($session_started == true) && (SESSION_FORCE_COOKIE_USE == 'False') ) {
if (defined('SID') && zen_not_null(SID)) {
$sid = SID;
// } elseif ( ( ($request_type == 'NONSSL') && ($connection == 'SSL') && (ENABLE_SSL_ADMIN == 'true') ) || ( ($request_type == 'SSL') && ($connection == 'NONSSL') ) ) {
} elseif ( ( ($request_type == 'NONSSL') && ($connection == 'SSL') && (ENABLE_SSL == 'true') ) || ( ($request_type == 'SSL') && ($connection == 'NONSSL') ) ) {
if ($http_domain != $https_domain) {
$sid = zen_session_name() . '=' . zen_session_id();
}

15 Sep 2015, 9:11 PM
#10
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: Make entire site SSL Only

tbohannon:

https://www.bodhisattva-store.com/listings/
ZC 1.5.0
Hosting on GoDaddy VPS
Dedicated SHA-2 SSL certificate to: https://www.bodhisattva-store.com managed through GoDaddy
Made changes in Store folder listings/includes/configure.php

define('HTTP_SERVER', 'http://www.bodhisattva-store.com');
define('HTTPS_SERVER', 'https://www.bodhisattva-store.com');

// Use secure webserver for checkout procedure?
define('ENABLE_SSL', 'true');
Made changes in Admin folder:
/listings/YOUR_SECRET_ADMN/includes/configure.php

/**

  • WE RECOMMEND THAT YOU USE SSL PROTECTION FOR YOUR ENTIRE ADMIN:
  • To do that, make sure you use a "https:" URL for BOTH the HTTP_SERVER and HTTPS_SERVER entries:
    */
    define('HTTP_SERVER', 'http://www.bodhisattva-store.com');
    define('HTTPS_SERVER', 'https://www.bodhisattva-store.com');
    define('HTTP_CATALOG_SERVER', 'http://www.bodhisattva-store.com');
    define('HTTPS_CATALOG_SERVER', 'https://www.bodhisattva-store.com');

// secure webserver for admin? Valid choices are 'true' or 'false' (including quotes).
define('ENABLE_SSL_ADMIN', 'true');

// secure webserver for storefront? Valid choices are 'true' or 'false' (including quotes).
define('ENABLE_SSL_CATALOG', 'true');

tbohannon:

As I posted I have all my http references pointing to the http URL and all https references point to the https URL.

So what am I missing here, other than poking around in the ncludes/functions/html_output.php you mentioned?

Thanks for responding!

Yes, you posted that is what you have, but those need to be changed to https: like below.

  define('HTTP_SERVER', 'https://www.bodhisattva-store.com');
  define('HTTPS_SERVER', 'https://www.bodhisattva-store.com');

  // Use secure webserver for checkout procedure?
  define('ENABLE_SSL', 'true');
Made changes in Admin folder:
/listings/YOUR_SECRET_ADMN/includes/configure.php

/**
 * WE RECOMMEND THAT YOU USE SSL PROTECTION FOR YOUR ENTIRE ADMIN:
 * To do that, make sure you use a "https:" URL for BOTH the HTTP_SERVER and HTTPS_SERVER entries:
 */
  define('HTTP_SERVER', 'https://www.bodhisattva-store.com');
  define('HTTPS_SERVER', 'https://www.bodhisattva-store.com');
  define('HTTP_CATALOG_SERVER', 'https://www.bodhisattva-store.com');
  define('HTTPS_CATALOG_SERVER', 'https://www.bodhisattva-store.com');

  // secure webserver for admin?  Valid choices are 'true' or 'false' (including quotes).
  define('ENABLE_SSL_ADMIN', 'true');

  // secure webserver for storefront?  Valid choices are 'true' or 'false' (including quotes).
  define('ENABLE_SSL_CATALOG', 'true');

This is similar to what DrByte discussed above. Otherwise multiple redirects occur when a redirect is only needed the one time. Namely the first click away from the page that was first landed on that was accessed by http: and even then the "redirect" is not the same as what is occurring via htaccess.

When SSL is set to true, then ZC uses the HTTPS_SERVER string when a page specifically is trying to use SSL such as login, contact_us (later versions of ZC to which you should migrate soon), checkout related pages, etc... Otherwise it uses the HTTP_SERVER string... Which if not set to https: will keep a user in the http: realm until 1) they enter https: to load a specific page or 2) they try to access a page designed to specifically use SSL when it is enabled. Otherwise if it is false, then it "always" uses HTTP_SERVER.

15 Sep 2015, 10:07 PM
#11
tbohannon avatar

tbohannon

New Zenner

Join Date:
Jan 2011
Posts:
9
Plugin Contributions:
0

Re: Make entire site SSL Only

Thank You!

Ok...changing all HTTP references to HTTPS in the 2 configure.php files fixed it!. I guess I did not understand the responses to direct me to make this simple change.

So with all the documentation I have seen on Google and this forum there is no mention of making sure that all HTTP references are changed to HTTPS. The guidance is to point HTTP > HTTP and HTTPS > HTTPS...so is required to point all HTTP/HTTPS references to HTTPS because I was Forcing SSL in my .htaccess file?

15 Sep 2015, 10:43 PM
#12
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: Make entire site SSL Only

tbohannon:

Thank You!

Ok...changing all HTTP references to HTTPS in the 2 configure.php files fixed it!. I guess I did not understand the responses to direct me to make this simple change.

So with all the documentation I have seen on Google and this forum there is no mention of making sure that all HTTP references are changed to HTTPS. The guidance is to point HTTP > HTTP and HTTPS > HTTPS...so is required to point all HTTP/HTTPS references to HTTPS because I was Forcing SSL in my .htaccess file?

So, the general consensus around here is that just because one search engine has adopted a particular view (the effect of which supposedly remain to be proven) does not mean that it need be adopted. But as to specifically what was going on, I can't say I know exactly how to explain the background details (assuming I knew them all to begin with) but can say that it seemed wrong that if I wanted https to appear everywhere that http was presented to "not" change the setting(s) in the file that has http: :)

Also, and I've seen a few threads in the last couple of days about this choice, but if not mistaken it is possible to tell google via webmaster tools that https: and http: pages are the same thing/site as part of this whole thing so that there is no SE "confusion". Anyways, glad it worked for you. Yes, some people need the "code" in front of them while others need it explained in words instead. :)

15 Sep 2015, 10:59 PM
#13
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Make entire site SSL Only

tbohannon:

https://www.bodhisattva-store.com/listings/
ZC 1.5.0
Hosting on GoDaddy VPS
Dedicated SHA-2 SSL certificate to: www.bodhisattva-store.com managed through GoDaddy

Added Forced SSL rules in .htaccess file...these are the only rules in the .htaccess file:
#Force SSL on entire site
RewriteEngine On
RewriteBase /
#RewriteCond %{ENV:HTTPS} !on [NC]
RewriteCond %{SERVER_PORT} 80
RewriteRule ^(.*)$ https://bodhisattva-store.com/$1 [R,L]
......

There is no need to force SSL in your .htaccess file, ZC takes care of this in the 2 configure.php files.

BTW, you should seriously consider upgrading your installation to the latest version.

15 Sep 2015, 11:20 PM
#14
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: Make entire site SSL Only

I also forgot to mention, it would seem that it is also time for you to change your admin directory name as it appears to have been published when posting the admin configure.php file (path to tell us it was the admin version.)

16 Sep 2015, 2:15 AM
#15
tbohannon avatar

tbohannon

New Zenner

Join Date:
Jan 2011
Posts:
9
Plugin Contributions:
0

Re: Make entire site SSL Only

frank18:

There is no need to force SSL in your .htaccess file, ZC takes care of this in the 2 configure.php files.

BTW, you should seriously consider upgrading your installation to the latest version.

Frank18,

Thanks for following up.

Yes agreed and we will be upgrading soon.

With regards to removing the Force SSL....if I remove that from .htaccess the site no longer shows https at the store level...only when I go to checkout.

So eager to hear how I can Force SSL on entire store if there is no need to put rules in .htaccess.

16 Sep 2015, 2:17 AM
#16
tbohannon avatar

tbohannon

New Zenner

Join Date:
Jan 2011
Posts:
9
Plugin Contributions:
0

Re: Make entire site SSL Only

mc12345678,

Thanks again for making this more clear.

So going to ask, is renaming the admin area as simple as renaming the folder on the server, or do I have to make code changes to the
store or theme?

16 Sep 2015, 2:21 AM
#17
tbohannon avatar

tbohannon

New Zenner

Join Date:
Jan 2011
Posts:
9
Plugin Contributions:
0

Re: Make entire site SSL Only

mc12345678:

So, the general consensus around here is that just because one search engine has adopted a particular view (the effect of which supposedly remain to be proven) does not mean that it need be adopted. But as to specifically what was going on, I can't say I know exactly how to explain the background details (assuming I knew them all to begin with) but can say that it seemed wrong that if I wanted https to appear everywhere that http was presented to "not" change the setting(s) in the file that has http: :)

The driver for this was not so much from Google's http/https identity crisis, as much as it was buyer concern over not seeing a padlock as soon as they
land on the site.

Several customers had called because they did not see a green padlock in Chrome, etc.

16 Sep 2015, 5:55 AM
#18
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Make entire site SSL Only

tbohannon:

Frank18,

Thanks for following up.

Yes agreed and we will be upgrading soon.

With regards to removing the Force SSL....if I remove that from .htaccess the site no longer shows https at the store level...only when I go to checkout.

So eager to hear how I can Force SSL on entire store if there is no need to put rules in .htaccess.

Store side configure.php

define('HTTP_SERVER', 'https://www.bodhisattva-store.com');
define('HTTPS_SERVER', 'https://www.bodhisattva-store.com');

Admin configure.php

/**

  • WE RECOMMEND THAT YOU USE SSL PROTECTION FOR YOUR ENTIRE ADMIN:
  • To do that, make sure you use a "https:" URL for BOTH the HTTP_SERVER and HTTPS_SERVER entries:
    */
    define('HTTP_SERVER', 'https://www.bodhisattva-store.com');
    define('HTTPS_SERVER', 'https://www.bodhisattva-store.com');
    define('HTTP_CATALOG_SERVER', 'https://www.bodhisattva-store.com');
    define('HTTPS_CATALOG_SERVER', 'https://www.bodhisattva-store.com');

Set all URL's to https: and that should do the trick.

16 Sep 2015, 7:34 AM
#19
tbohannon avatar

tbohannon

New Zenner

Join Date:
Jan 2011
Posts:
9
Plugin Contributions:
0

Re: Make entire site SSL Only

frank18,

Thanks for re-confirming the changes I made to clear the 2 issues I originally posted about.
I set all http references to https as you suggested.

So my remaining issue now is you say I can remove the Force SSL .htaccess rules, but when I do remove the rules
store level is no longer protected, only when checking out.

16 Sep 2015, 8:03 AM
#20
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Make entire site SSL Only

tbohannon:

frank18,

Thanks for re-confirming the changes I made to clear the 2 issues I originally posted about.
I set all http references to https as you suggested.

So my remaining issue now is you say I can remove the Force SSL .htaccess rules, but when I do remove the rules
store level is no longer protected, only when checking out.

Did you clear the cache of your browser or used another browser? If not, that could be the issue.