spawnie69:
I have 2 live sites of 1.39h site at gelcandlecompany.com and www.gelcandlecompany.com/wholesale
and 3 demo 1.54 stores running responsive templates at /demo, /demo2, and /demo3
I can't seem to get a single SSL page to display at all sites, do I change all configure files? or just the 2 live sites
Thank you RodG
So, if I'm reading this correctly you are saying that the SSL is actually working OK on at least one of these sites? Which one?
I've tried various permutations of URLs based on the information you've provided and SSL is failing on all of them.
The thlot pickens.
How about we try a different approach?
Firstly though, if you are using a host supplied shared SSL then please go away. You aren't serious about site security. Testing, debugging, and configuration of such installions can be a nightmare even with a single site on a single host.
Your setup (based on what you have written) consists of two different hosts each with a live zencart. (which may or may not have their own top level folders), plus three demo sites that reside in a folder from one of these hosts, and no indication as to which of the two hosts you are wanting to use to access the demo sites.
It gets worse. If you use SSL, you now have three different hosts to consider, and possibly even four if you want the SSL to be valid for the two current hosts.
The SSL for the sites residing in the folders will be using the same SSL certificate as the parent site, keeping in mind that the certificates are issued (valid for) only a *single host, of which you have two.
*At this point someone usually steps in to tell me that these days you can get an SSL certificate for multiple host, which is true, but that is a whole new ballgame and a different discussion.
So, have I got you confused yet? Yes? Good, because if you your aren't then it means you are possibly trying to achieve the unachievable, and that is why you can't get it to all play nicely together.
Ok, so now let me try to give you some info that I'm hoping will help you diagnose the SSL issue.
Firstly, the two live sites gelcandlecompany.com & https://www.gelcandlecompany.com really are different hosts. An SSL certificate issued for one will not be valid for the other.
This simple fact is invariably going to be the root cause of your problem, especially considering that you stated "I can't seem to get a single SSL page to display at all sites".
You must be consistent with you "www" (or lack of).
You will need to determine which of these the certificate was issued for and use that in all config settings for all sites hosted on that server.
This consistency all means that you can now ignore most of the confusing stuff I wrote as it will no longer be relevant.
You are now down to a single host, and a single SSL that matches that host.
Please note, up until this point, zencart (and it's settings) haven't been mentioned, and even though these could be well messed up, now is not the time to worry about them.
The first (and only) thing you need to do is ensure that the host can correctly respond to both SSL and non SSL requests.
Simple to do. If the certificate is issued for "www.gelcandlecompany.com" then enter
"http://www.gelcandlecompany.com" into your Web browser and verify that the page displayed a) actually displays a valid page rather than an error message, and b) the address you entered is the same as the page you are seeing. The only permitted change being the possible addition of /something after the com.
Repeat this same test, but this time, enter "https" rather than just "http"
Again, the page displayed (regardless what it is) should be valid (not an error) and the URL should remain the same as entered.
If you DON'T get these expected results it means that you either have some sort of URL rewriting going on, and/or the SSL installation is incorrect.
Whichever it is, it will need to be rectified before diving any deeper.
If you find the URL you enter gets changed so that the "www" is added or removed you will then need to go to the zencart config settings of the sites that was displayed (the one in the top lever (root) folder and change the server defines so they match your SSL (IOW, add/remove the "www" As appropriate)
Repeat the two tests.
When, and only when both tests succeed you should go back to the zencart configs and enable the SSL. Take note, the tests I've suggested will/should/must function correctly regardless of whether the SSL has been enabled in the configs or not. This setting is effectively overwritten (doesn't come into play) when you access the site via the URL. Understanding this is very useful, because if it's not immediately obvious, you now know how to test the SSL capability/functionality of ANY website on the planet (including all of yours) - SSL is a function of the server, not the software hosted on the server.
At this stage, the site in the root folder of the host should now be fully functional and after the first access, will automatically switch between SSL and non SSL pages as appropriate.
The main thing for you to take home here is that you don't need to enable/disable the SSL settings in any of your current five zencart installs to see if they will work or not.
The idea being is that you should verify that they do function correctly, and then enable.
Your next step is to tackle the site that you have located in the folders (sub folders)
This is just a matter of repeating the URL tests, but instead of just entering
"www.gelcandlecompany.com" you'll need to include the folder names, eg
"http://www.gelcandlecompany.com/wholesale/" and
"https://www.gelcandlecompany.com/wholesale/"
and
"http://www.gelcandlecompany.com/demo/"
"https://www.gelcandlecompany.com/demo/"
If/when these tests pass (no errors, no strange URL rewrites (other than the possible additional stuff after the last / you can go to the zencart configs and enable the SSL.
If the URL tests/checks Do pass, but things fall over when navigation the site(s) , then you will be needing to look at the zencart configs for the troublesome sites. You will no longer be looking (or even thinking) about the SSL.. That aspect of things has already been tested and verified.
So, I've started out trying to confuse you... Because, well, it is confusing if/when you try to look at the big picture, but I'm hoping that by breaking it down to the various components in a step by step manner it has become a little clearer as to how all the various pieces fit together, and possibly even shown where /why things are going wrong. .. As a general rule (and in my experience) few people seem to consider that entering something in the browser address bar, and then observing what is shown (on both the page and the returned URL) is a very good diagnostic tool that can eliminate a lot of trial and error that comes about from messing with various config settings.
Hopefully this helps.
Cheers
RodG