Forums / General Questions / HTTPS not showing information....

HTTPS not showing information....

Views: 3,183

Results 1 to 20 of 29
5 Mar 2015, 11:52 PM
#1
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

HTTPS not showing information....

I have three domains that just got SSL added to them and when I go to the https://mydomain.com the template doesn't show the template that I modified or any of the graphics....just shows raw content all over. I know this is something simple but I've searched and can't find the answer. The regular domains work great. Here is what I've put in the config files so far -

  define('HTTP_SERVER', 'http://www.mydomain.com');
  define('HTTPS_SERVER', 'https://www.mydomain.com');
  define('HTTP_CATALOG_SERVER', 'http://www.mydomain.com');
  define('HTTPS_CATALOG_SERVER', 'https://www.mydomain.com');

  // secure webserver for admin?  Valid choices are 'true' or 'false' (including quotes).
  define('ENABLE_SSL_ADMIN', 'true');

  // secure webserver for storefront?  Valid choices are 'true' or 'false' (including quotes).
  define('ENABLE_SSL_CATALOG', 'true');


  define('DIR_WS_ADMIN', preg_replace('#^' . str_replace('-', '\-', zen_parse_url(HTTP_SERVER, '/path')) . '#', '', dirname($_SERVER['SCRIPT_NAME'])) . '/');
  define('DIR_WS_CATALOG', '/');
  define('DIR_WS_HTTPS_ADMIN', preg_replace('#^' . str_replace('-', '\-', zen_parse_url(HTTPS_SERVER, '/path')) . '#', '', dirname($_SERVER['SCRIPT_NAME'])) . '/');
  define('DIR_WS_HTTPS_CATALOG', '/');

// NOTE: be sure to leave the trailing '/' at the end of these lines if you make changes!
// * DIR_WS_* = Webserver directories (virtual/URL)
  // these paths are relative to top of your webspace ... (ie: under the public_html or httpdocs folder)
  define('DIR_WS_IMAGES', 'images/');
  define('DIR_WS_ICONS', DIR_WS_IMAGES . 'icons/');
  define('DIR_WS_CATALOG_IMAGES', HTTP_CATALOG_SERVER . DIR_WS_CATALOG . 'images/');
  define('DIR_WS_CATALOG_TEMPLATE', HTTP_CATALOG_SERVER . DIR_WS_CATALOG . 'includes/templates/');
  define('DIR_WS_INCLUDES', 'includes/');
  define('DIR_WS_FUNCTIONS', DIR_WS_INCLUDES . 'functions/');
  define('DIR_WS_CLASSES', DIR_WS_INCLUDES . 'classes/');
  define('DIR_WS_MODULES', DIR_WS_INCLUDES . 'modules/');
  define('DIR_WS_LANGUAGES', DIR_WS_INCLUDES . 'languages/');
  define('DIR_WS_CATALOG_LANGUAGES', HTTP_CATALOG_SERVER . DIR_WS_CATALOG . 'includes/languages/');

// * DIR_FS_* = Filesystem directories (local/physical)
  define('DIR_FS_ADMIN', preg_replace('#.includes$#', '', realpath(dirname(__FILE__) . '/../') . '/'));

  define('DIR_FS_CATALOG', '/home/maindomain/public_html/mydomain/');

  //the following path is a COMPLETE path to the /logs/ folder  eg: /var/www/vhost/accountname/public_html/store/logs ... and no trailing slash
  define('DIR_FS_LOGS', DIR_FS_CATALOG . '/logs');

  define('DIR_FS_CATALOG_LANGUAGES', DIR_FS_CATALOG . 'includes/languages/');
  define('DIR_FS_CATALOG_IMAGES', DIR_FS_CATALOG . 'images/');
  define('DIR_FS_CATALOG_MODULES', DIR_FS_CATALOG . 'includes/modules/');
  define('DIR_FS_CATALOG_TEMPLATES', DIR_FS_CATALOG . 'includes/templates/');
  define('DIR_FS_BACKUP', DIR_FS_ADMIN . 'backups/');
  define('DIR_FS_EMAIL_TEMPLATES', DIR_FS_CATALOG . 'email/');
  define('DIR_FS_DOWNLOAD', DIR_FS_CATALOG . 'download/');

// define our database connection
  define('DB_TYPE', 'mysql');
  define('DB_PREFIX', 'zc_');
  define('DB_CHARSET', 'utf8');
  define('DB_SERVER', 'localhost');
  define('DB_SERVER_USERNAME', ' *********** ');
  define('DB_SERVER_PASSWORD', ' ********** ');
  define('DB_DATABASE', ' *********** ');

  // The next 2 "defines" are for SQL cache support.
  // For SQL_CACHE_METHOD, you can select from:  none, database, or file
  // If you choose "file", then you need to set the DIR_FS_SQL_CACHE to a directory where your apache
  // or webserver user has write privileges (chmod 666 or 777). We recommend using the "cache" folder inside the Zen Cart folder
  // ie: /path/to/your/webspace/public_html/zen/cache   -- leave no trailing slash
  define('SQL_CACHE_METHOD', 'file');
  define('DIR_FS_SQL_CACHE', DIR_FS_CATALOG.'cache');

Any help greatly appreciated.... :shocking:

5 Mar 2015, 11:59 PM
#2
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

I just read that some of the information loaded is coming from http in stead of https and that what's causing it but how do I change everything if the site is already up and running?

6 Mar 2015, 12:02 AM
#3
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: HTTPS not showing information....

That's your admin configure.php, or at least it is what would be expected in it.

Also, the https server info needs to match what your cert is for (ie, www. Being present or not)

Also the two non catalog server addresses should begin with https with both switches set to true as it is.

ZC Installation/Maintenance Support <- Site
Contribution for contributions welcome...

6 Mar 2015, 12:15 AM
#4
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

Okay, I'm on it....

6 Mar 2015, 1:15 AM
#5
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

Okay changing the address made the entire show but it still has the yellow exclamation point over the lock in the address bar. How do I fix that? This is what I get from the exclamation - Attachment 15038

I would also like to force the site to use encryption all the time.... :cool:

6 Mar 2015, 1:39 AM
#6
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: HTTPS not showing information....

We'd help you identify the specifics, but you haven't provided a URL, so it's impossible to do that.

But here's what you need to do: http://www.zen-cart.com/content.php?185-this-page-contains-both-secure-and-nonsecure-items-%28or-unauthenticated-content-or-connection-partially-encrypted%29

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

6 Mar 2015, 4:07 AM
#7
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

DrByte:

We'd help you identify the specifics, but you haven't provided a URL, so it's impossible to do that.

But here's what you need to do: http://www.zen-cart.com/content.php?185-this-page-contains-both-secure-and-nonsecure-items-%28or-unauthenticated-content-or-connection-partially-encrypted%29

Oh, sorry about that I forgot....

https://bigboybaitco.com

Great link I'm sure that's what it is now because I had to do that a couple of times. If I got into the zencart I should be able to find all the culprits doing a search using the tools in there yes?

6 Mar 2015, 6:09 PM
#8
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

DrByte:

We'd help you identify the specifics, but you haven't provided a URL, so it's impossible to do that.

But here's what you need to do: http://www.zen-cart.com/content.php?185-this-page-contains-both-secure-and-nonsecure-items-%28or-unauthenticated-content-or-connection-partially-encrypted%29

Okay, I went into the websites and their riddle with http:// references. Should I have installed the SSL first then installed the website. It would take me a long time to go through everything. here are the links to the websites I'm dealing with -

 tackleandrod.com
 blackwidowarms.com
 bigboybaitco.com

..... their secure but it has that error as above when I posted the image. Any suggestions?????:shocking:

6 Mar 2015, 6:21 PM
#9
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

micro007:

Okay, I went into the websites and their riddle with http:// references. Should I have installed the SSL first then installed the website. It would take me a long time to go through everything. here are the links to the websites I'm dealing with -

 tackleandrod.com
 blackwidowarms.com
 bigboybaitco.com

..... their secure but it has that error as above when I posted the image. Any suggestions?????:shocking:

I just thought about this: when I added images there were all relative, I didn't add http:// .....

6 Mar 2015, 8:23 PM
#10
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

I'm on the line with godaddy and they're telling me I have a sha-2 certificate but chrome is seeing it as sha-1, does this tip anyone off? I read a document on the internet where chrome will throw this type of error without anything being wrong. I also don't get the error with IE or Firefox - just chrome.............

6 Mar 2015, 9:32 PM
#11
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

Well, none of this has alleviated the problem.

  1. I've changed the config.php files in all areas which the site now works in both modes but I still get the error.....
  2. I've also followed the link - http://www.zen-cart.com/content.php?...lly-encrypted) and changed everything to https:// or removing the and making it relative to the domain. Still I get the error.....

I can't believe no one has encountered this before..... really weird

6 Mar 2015, 10:15 PM
#12
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: HTTPS not showing information....

micro007:

Should I have installed the SSL first then installed the website.

The sequence of these two is not as important as knowing that the SSL works properly before forcing the site to use it...

It could have been installed in either order, but with the SSL switch in the configure.php files off. Or installed with them on, but at least a test file should have been loaded as secure to verify that it worked before turning it on...

ZC Installation/Maintenance Support <- Site
Contribution for contributions welcome...

6 Mar 2015, 10:46 PM
#13
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

mc12345678:

The sequence of these two is not as important as knowing that the SSL works properly before forcing the site to use it...

It could have been installed in either order, but with the SSL switch in the configure.php files off. Or installed with them on, but at least a test file should have been loaded as secure to verify that it worked before turning it on...

So, your telling me I have a problem, it would have shown up if I would have installed and tested first, but there is no answer to solve the problem?:dontgetit

6 Mar 2015, 11:08 PM
#14
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: HTTPS not showing information....

micro007:

but there is no answer to solve the problem?:dontgetit

Didn't say there is no solution... I didn't have it at the time of posting above, but I plan to try to search for what you are describing of chrome not recognizing the certificate at level 2 but instead at level 1 (level used because I couldn't remember the specific terminology from the previous post, but I have an understanding of the issue.) Does make me wonder if it is a specific settting of the browser though. I know that like IE offers choosing which method of communication such as SSL3, TLS 1 or TLS 2 to be used from the browser side, makes me wonder if there is such a "switch" in chrome...

ZC Installation/Maintenance Support <- Site
Contribution for contributions welcome...

6 Mar 2015, 11:17 PM
#15
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: HTTPS not showing information....

So, having doin an internet search, I found at least one item that discussed this issue. There were several others with similar information, but it seem that at least this one provides some discussion about how to resolve it. :http://www.wordfence.com/blog/2014/11/wordpress-security-reminder-upgrade-ssl-certificates-sha1-sha2/

Appears to be specifically a certificate issue and that the latest version of the certificate is not being used (or perhaps the browser is a bit outdated? What version of chrome is being used?

ZC Installation/Maintenance Support <- Site
Contribution for contributions welcome...

7 Mar 2015, 4:06 AM
#16
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: HTTPS not showing information....

Using Chrome Dev Tools and looking at the Console tab, I see:

Mixed Content: The page at 'https://tackleandrod.com/' was loaded over HTTPS, but requested an insecure stylesheet 'http://fonts.googleapis.com/css?family=Telex'. This request has been blocked; the content must be served over HTTPS.

Mixed Content: The page at 'https://tackleandrod.com/' was loaded over HTTPS, but requested an insecure script 'http://code.jquery.com/jquery-latest.js'. This request has been blocked; the content must be served over HTTPS.
select2.js:21

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

7 Mar 2015, 7:35 PM
#17
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

DrByte:

Using Chrome Dev Tools and looking at the Console tab, I see:

Mixed Content: The page at 'https://tackleandrod.com/' was loaded over HTTPS, but requested an insecure stylesheet 'http://fonts.googleapis.com/css?family=Telex'. This request has been blocked; the content must be served over HTTPS.

Mixed Content: The page at 'https://tackleandrod.com/' was loaded over HTTPS, but requested an insecure script 'http://code.jquery.com/jquery-latest.js'. This request has been blocked; the content must be served over HTTPS.
select2.js:21

Okay, that makes sense. So, I've made a ton of work for myself by adding the SSL after the website? Is there an easier way that going through all these calls, or will I have to do it one by one? Oh, and I know I can go through and change all the template info by doing a mass change of the http to https but, will doing that small change screw up the links at which these things are mapped to? Another words making them useless?

On another note what is the proper way to do this? Should I have installed the Zen Cart then added the SSL and forced the site into secure mode then installed everything or would I have still had this problem of links?

Thanks for all the help you guys are a life saver....!!!!:blush:

8 Mar 2015, 4:39 AM
#18
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: HTTPS not showing information....

micro007:

On another note what is the proper way to do this? Should I have installed the Zen Cart then added the SSL and forced the site into secure mode then installed everything or would I have still had this problem of links?
You would still have had this problem.

It's not a matter of "order of operations". It's just that you, or whatever templates/mods/plugins/customizations you've added haven't taken into account the need to be "relative URLs instead of absolute", or else protocol-agnostic by using "//" instead of "http://" or "https://"

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

8 Mar 2015, 5:10 AM
#19
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

DrByte:

You would still have had this problem.

It's not a matter of "order of operations". It's just that you, or whatever templates/mods/plugins/customizations you've added haven't taken into account the need to be "relative URLs instead of absolute", or else protocol-agnostic by using "//" instead of "http://" or "https://"

Okay, so I'm going to go through the site now and replace https and http with // is that true? Should I just leave out the beginning protocol and just use https://www.whatever.com/whatever in the call out throughout the template?

8 Mar 2015, 3:13 PM
#20
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: HTTPS not showing information....

micro007:

Okay, so I'm going to go through the site now and replace https and http with // is that true? Should I just leave out the beginning protocol and just use www.whatever.com/whatever in the call out throughout the template?

I don't wish to confuse you, but there are actually three 'types' of links that can be used.

  1. Absolute links.
    Examples
    http://somesite.com
    http://somesite.com/some/path/file.html
    https://somesite.com
    https://somesite.com/some/path/file.php
    http://yoursite.com
    http://yoursite.com/some/path/file.html
    https://yoursite.com
    https://yoursite.com/some/path/file.php

  2. Relative links.
    Examples
    index.php
    /some/path/file.php
    /some/other/path/file.html

3) Protocol-agnostic links
Examples
//notMySite.com
//YetAnotherSite.com/some/path/file.html

Absolute links are 'robust' but not 'portable' . They can be/are used primarily to force the use of a specific protocol (http, https, ftp. file, etc). Although these links can point to your own domain name this isn't recommended as it causes an additional DNS lookup. It can also make things more complicated than they need be if the site needs to be migrated to a different domain.

Relative links can only be used to link to resources on your own site. In almost all cases these are the best ones to use where and when possible. The code is easily portable and there are no issues with http vs https.

Protocol-agnostic links are somewhat of a hybrid of the Absolute and Relative links. They are used primarily for offsite linking where the protocol either can't be explicitly set or where it isn't practical to do so.

ZenCart makes extensive use of dynamically generated Absolute Links as this enables HTTP/HTTPS to be explicitly given (essential for directing the client between SSL enabled and No SSL parts of the site).
Almost all 'user defined' links (eg, internal EZ-Page links, most links in the template files, and the links in most add-ons that don't need to connect to offsite/external servers will/should be using Relative links.

Protocol-agnostic links should (at least in my opinion) only be used as a last resort in place of Absolute links to external servers if the protocol can't be dynamically assigned.

So, to answer you question as to whether you should go through the site and change all links to be protocol-agnostic, the answer is no. Only change the ones that are actually needed.

Cheers
RodG

   

NOTE: We are sorry that Rod is no longer with us.
We are grateful for all his contributions to the Zen Cart community.

Ozpost - The Ultimate Shipping module for Australian Merchants. Click these links for its Homepage, or Download from Zen-Cart.com.