Page 1 of 2

Re: Redirect forums to https

Posted: Mon Nov 13, 2017 9:06 pm
by PeterJ
Thanks, I will need to research this.

Re: Redirect forums to https

Posted: Mon Nov 13, 2017 9:08 pm
by R-Tape
I have no idea if it's relevant, only that Mike mentioned it, but the last one is the only page with 'www', though the problem was the page before that.

Re: Redirect forums to https

Posted: Mon Nov 13, 2017 9:14 pm
by PeterJ
OK, I have made a another change (Thanks to Mike for the clue). I get an error with the first page of this topic, but nowhere else.

Re: Redirect forums to https

Posted: Mon Nov 13, 2017 9:15 pm
by Ralf
And now it's working okay. Did you change anything?

Re: Redirect forums to https

Posted: Mon Nov 13, 2017 9:18 pm
by R-Tape
Working for me too, no errors. Hopefully that's that, well done.

Re: Redirect forums to https

Posted: Mon Nov 13, 2017 9:31 pm
by PeterJ
Ralf wrote: Mon Nov 13, 2017 9:15 pm And now it's working okay. Did you change anything?
There was a random www in one of the security settings.
phpBB is not the easiest system to configure. Glad it's working. Over and out for tonight.

Re: Redirect forums to https

Posted: Mon Nov 13, 2017 11:22 pm
by Stefan
PeterJ wrote: Mon Nov 13, 2017 9:14 pm OK, I have made a another change (Thanks to Mike for the clue). I get an error with the first page of this topic, but nowhere else.
You're getting the error on the first page due to R-Tape's screen shot coming from elsewhere: http://stonechatproductions.co.uk/zxgam ... SCperm.gif

There should be a setting or module available for phpBB to support this.

Maybe see: https://area51.phpbb.com/phpBB/viewtopic.php?t=50956 and https://github.com/phpbb-extensions/camosslimageproxy

No idea if these are any good.

Re: Redirect forums to https

Posted: Tue Nov 14, 2017 9:13 am
by dfzx
Not quite there... :)

spectrumcomputing.co.uk correctly redirects to https://spectrumcomputing.co.uk/

www.spectrumcomputing.co.uk correctly redirects to https://spectrumcomputing.co.uk/

http://spectrumcomputing.co.uk/ correctly redirects to https://spectrumcomputing.co.uk/

http://www.spectrumcomputing.co.uk correctly redirects to https://spectrumcomputing.co.uk/

But!

https://www.spectrumcomputing.co.uk/ doesn't redirect. It complains about the certificate domain being wrong.

Re: Redirect forums to https

Posted: Wed Nov 15, 2017 11:17 pm
by tez
PeterJ wrote: Mon Nov 13, 2017 9:00 pm If there are any security experts out there who can help please send me a PM.
Long-time WoS lurker but registering here to offer some assistance :D

The SSL certificate presented here is only valid for 'spectrumcomputing.co.uk' but not 'www.spectrumcomputing.co.uk'.

You can see this here: https://www.ssllabs.com/ssltest/analyze ... Results=on

As you can see, the certificate does not list 'www.spectrumcomputing.co.uk' anywhere so any client who tries to access via 'www.spectrumcomputing.co.uk' will fail to validate the certificate.

The solution is to reconfigure your LetsEncrypt client to request a certificate containing both names; feel free to PM me if you need some help in doing this.

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 12:17 pm
by HexTank
In firefix there's a warning about connection not being secure, "Parts of this page are not secure (such as images)"

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 12:23 pm
by Mike Davies
HexTank wrote: Thu Nov 16, 2017 12:17 pm In firefix there's a warning about connection not being secure, "Parts of this page are not secure (such as images)"
Can you paste in the URL of the page you are seeing this warning on?
It's typically because one or more of the images, or embeds on the page isn't an https reference.

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 12:34 pm
by 1024MAK
All pages do it. I think it is either the logo picture, or the associated link: http://spectrumcomputing.co.uk/

EDIT: it's the link, as loading the GIF image alone does not generate the warning.

Mark

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 12:49 pm
by HexTank
Yes, as Mark said, it happens everywhere, even this thread :)

viewtopic.php?f=29&t=37&p=580#p580 for reference.

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 12:56 pm
by PeterJ
Hello. It's pages where users have inserted images hosted elsewhere. This page of this thread is currently fine.

I'm aware of the issue, and need to find a time to look at fixes, but for now it is as it is. Sorry.

Someone posted some possible solutions earlier in the week that I will look at.

Peter

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 1:01 pm
by 1024MAK
I did my investigations on the FAQ page...
No user images or links there as far as I could see...

Mark

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 1:07 pm
by PeterJ
OK. Thanks Mark. I will continue looking. I'm using Chrome and I get the full secured site on that page, but will install Firefox and try it. We are out this weekend but will make it a priority.

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 1:14 pm
by Mike Davies
HexTank wrote: Thu Nov 16, 2017 12:49 pm Yes, as Mark said, it happens everywhere, even this thread :)

viewtopic.php?f=29&t=37&p=580#p580 for reference.
@HexTank, @1024MAK, are you seeing the same issue on this page:
https://spectrumcomputing.co.uk/index.php?cat=4 -- the Contact page?

Also, which version of Firefox are you running, what operating system?
Are you running any plugins or extensions that may inject markup on the page, for example an "Instagram this!" button on images?

I've checked the pages listed on Vivaldi, and Firefox on my Mac (El Capitan), and no warnings produced.

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 1:16 pm
by PeterJ
Thanks for the testing Mike. SSL is new to me.

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 1:21 pm
by Mike Davies
PeterJ wrote: Thu Nov 16, 2017 1:16 pm Thanks for the testing Mike. SSL is new to me.
Me too. :-)
Just trying to replicate the problem, then we can figure out what's going on.

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 2:00 pm
by HexTank
@Mike no, seems fine there.

Re: Redirect forums to https

Posted: Thu Nov 16, 2017 3:03 pm
by 1024MAK
On the machine that I'm currently using, the browser is Firefox 56.0 (32-bit), which is running on a Linux OS.
Note that Safari on an iPad mini does not produce this warning.

The Firefox browser does have various plugins, but none inject mark-up on any pages and it is fine on other secure sites.

The pages I did my testing on are the forum index page (index.php) and the FAQ page (app.php/help/faq).

On the index page, the only non https:// links that I can see are:
http://cookiesandyou.com/
http://spectrumcomputing.co.uk/ (which is what you get if you click on the logo)

As this forum does not allow attachments, I can't directly attach images showing the problem.
If you want to see the images, let me know and later I will post them up elsewhere and link to them (I wonder if that will also add to the problem :mrgreen: ).

Mark