Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

Security Problems


Guest

Recommended Posts

Posted

Someone earlier helped me set the configure.php file up. My problem is, that everyone has stated that osCommerce will automatically throw your site into secure mode when you go to account or checkout. This has not happened for me.

 

I have SSL turned on, but have not purchased any security certs.

 

Thanks for the advanced help

 

// Define the webserver and path parameters

// * DIR_FS_* = Filesystem directories (local/physical)

// * DIR_WS_* = Webserver directories (virtual/URL)

define('HTTP_SERVER', 'http://www.tech2ucrew.com');

define('HTTPS_SERVER', 'https://www.tech2ucrew.com');

define('ENABLE_SSL', true); // secure webserver for checkout procedure?

define('HTTP_COOKIE_DOMAIN', 'www.tech2ucrew.com');

define('HTTPS_COOKIE_DOMAIN', 'www.tech2ucrew.com');

define('HTTP_COOKIE_PATH', '/store/');

define('HTTPS_COOKIE_PATH', 'www.tech2ucrew.com');

define('DIR_WS_HTTP_CATALOG', '/store/');

define('DIR_WS_HTTPS_CATALOG', '/store/');

define('DIR_WS_IMAGES', 'images/');

define('DIR_WS_ICONS', DIR_WS_IMAGES . 'icons/');

define('DIR_WS_INCLUDES', 'includes/');

define('DIR_WS_BOXES', DIR_WS_INCLUDES . 'boxes/');

define('DIR_WS_FUNCTIONS', DIR_WS_INCLUDES . 'functions/');

define('DIR_WS_CLASSES', DIR_WS_INCLUDES . 'classes/');

define('DIR_WS_MODULES', DIR_WS_INCLUDES . 'modules/');

define('DIR_WS_LANGUAGES', DIR_WS_INCLUDES . 'languages/');

Posted
Someone earlier helped me set the configure.php file up.  My problem is, that everyone has stated that osCommerce will automatically throw your site into secure mode when you go to account or checkout.  This has not happened for me.

 

I have SSL turned on, but have not purchased any security certs. 

 

Thanks for the advanced help

You'll have to get an SSL Certificate or find out if your host has a shared certificate. Also, remember that there are two configure.php files (catalog/includes and catalog/admin/includes).

Posted

i think i might be using a shared cert, b/c when i connect to my site, it asks for a security acceptance.

Posted

You may have access to a shared ssl from your hosting company, but you are not using it.

 

The reason you are getting the security alert is because in the file you posted you have ENABLE_SSL set to 'true', and you have given an https address for a website with a full ssl certificate installed - when you have no ssl at all.

 

Vger

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...