Jump to content
IGNORED

Major Site Update: HTTPS/SSL Support


BowhunterNJ

Recommended Posts

Hey guys and gals, just wanted to let you know I am in the process of converting the site to full HTTPS/SSL to give you guys that warm fuzzy feeling of being ultra secure while visiting the site! This really is just in an effort to promote better security, especially as new transaction based features get rolled out, as it will help protect your personal information! :up:

 

From a member's perspective, everything *should* remain the same in respect to navigating the site. There may be some hiccups during the transition, so if you see any issues, please do report them.

 

 

For those that want more info on this update, or are super geeks like Haskell_Hunter...

 

You should see most pages will not contain the https:// identifier and a certificate bound to it as depicted in the following images.

 

This is the new address bar will appear under most conditions, as often times content gets linked from external entities (i.e. images/videos from other sites that may not be running under HTTPS). This only means that some of the content being displayed is not secure, but the content being served via NJ Woods & Water will be.

mixedContent.JPG

 

 

When all of the content is 100% secured via HTTPS, you will see the following type of address part with the green bar and the company name, that should make you REALLY warm and fuzzy! :D

NoMixedContent.JPG

 

 

And if you click the little icon to the left of the HTTPS:// in the address bar, you'll see the certificate for the site. :up:

Cert.jpg

 

 

That's all I have for now, but again, if you see any issues at all, please let me know and I'll get them sorted out ASAP! :up:

Link to comment
Share on other sites

Thank God!

 

The https and ssls were so ten minutes ago.

 

This was of major concern to me. I'm so excited that you're going to fix it....So exhilarating in fact, my floppy disk turned into a hard drive!

 

I'd really like to see what we can do about the www thing too....maybe upgrade to yyy or zzz.

 

I'd just feel better about the site if you could make those changes...MMMMK? Thanks....

Edited by Matty

“I have always tempered my killing with respect for the game pursued. I see the animal not only as a target, but as a living creature with more freedom than I will ever have. I take that life if I can, with regret as well as joy, and with the sure knowledge that nature’s way of fang and claw and starvation are a far crueler fate than I bestow.” – Fred Bear

Link to comment
Share on other sites

lol

“I have always tempered my killing with respect for the game pursued. I see the animal not only as a target, but as a living creature with more freedom than I will ever have. I take that life if I can, with regret as well as joy, and with the sure knowledge that nature’s way of fang and claw and starvation are a far crueler fate than I bestow.” – Fred Bear

Link to comment
Share on other sites

Did you get a UCC or wildcard cert?  You probably want to force your mail server to use TLS as well. 

 

Is is the site single-tier or two?  You should cert the dB as well, hence the UCC.

I got a Extended Validation (EV) SSL Certificates. I only have one domain (well two if you consider www and non-www versions, but it supports both), not porting to subdomains so opted out of the wildcard matching.

I'm NOT a security/server admin, so learning as I go...next time I'm working with you on this! :)

Honestly, this was to help support secure transactions in the future (as I will open the storefront here and handle things like donations directly).

Likewise many apps/sites out there are running full SSL for all content, so I figured I'd upgrade the entire site versus just the storefront.

I'll have to double check on the mail server security and DB security.

 

BnB, I fixed that issue, now the old bookmarks will redirect OK without warning. This is mainly due to the old NJFNG links :)

Link to comment
Share on other sites

I went with a UCC for my site because I use more than one server to host services. So being able to extend the same cert to mail. www. dB. was really handy to have. From a security perspective, splitting the services onto different boxes protects the environment. Just because you got onto my app server doesn't mean you'll be able to access my mail, admin, or data. 

 

Oh, and re-certing all of your services is going to suck. Depends on the platform, but it is annoying to do. 

 

Regardless, it's a really good move, and I'm glad you took the initiative to do it.

Sapere aude.

Audeamus.

When you cannot measure, your knowledge is meager and unsatisfactory.

Link to comment
Share on other sites

Says "reboot".

 

I've tried on three different pairs now and nothing has changed. I guess I'll try my knee high rubber boots....

“I have always tempered my killing with respect for the game pursued. I see the animal not only as a target, but as a living creature with more freedom than I will ever have. I take that life if I can, with regret as well as joy, and with the sure knowledge that nature’s way of fang and claw and starvation are a far crueler fate than I bestow.” – Fred Bear

Link to comment
Share on other sites

As long as it won't get me banned... :rofl:

“I have always tempered my killing with respect for the game pursued. I see the animal not only as a target, but as a living creature with more freedom than I will ever have. I take that life if I can, with regret as well as joy, and with the sure knowledge that nature’s way of fang and claw and starvation are a far crueler fate than I bestow.” – Fred Bear

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...