Not secure address

What can the Admins do to help, any requests for changes, updates, etc.
User avatar
Bigyin
Posts: 3179
Joined: Sun Mar 15, 2020 7:39 pm
Has thanked: 1412 times
Been thanked: 2680 times

Not secure address

Post by Bigyin »

I assume its a time related issue that will be resolved but is there a problem with the "not secured" web address for the forum as it currently stands
User avatar
weeksy
Site Admin
Posts: 23417
Joined: Sat Mar 14, 2020 12:08 pm
Has thanked: 5450 times
Been thanked: 13085 times

Re: Not secure address

Post by weeksy »

Well in simple IT nerdy speak, yes, it needs 'sorting' but don't think for a second this makes anything actually 'insecure'. No-one can hack your PC etc because you've visited this site. Basically it uses what's known as a self-signed certificiate and i need to use the server information to created what's known as a CSR, send that to a certificate authority and they then send me back a digitally signed certificate which i then re-import back into the server and everything is then digitally 'signed'.

I'll get it sorted in the future, but the only thing it affects is things like entering Credit Card details on here could be classed as insecure, which i'm not intending on people doing.

The downside to this is that the cost is quite prohibitive depending on the levels we go for.

https://www.hosting.co.uk/ssl/?_ga=2.12 ... 1584124442

In work we use SSL certs of course for many applications, we send ours out to a 3rd party, but that's all sorted 'internally' so there's no actual associated costs for it... Obviously looking at this link, there's deffo a cost associated, so i need to research which level of SSL, why and then weigh up costs over requirements etc

It's on the list :)
User avatar
weeksy
Site Admin
Posts: 23417
Joined: Sat Mar 14, 2020 12:08 pm
Has thanked: 5450 times
Been thanked: 13085 times

Re: Not secure address

Post by weeksy »

OK, here's where we are now :)

After some fangled clicking, checking, testing and a bit of Paypal, we now have a secured website and forum.

https://revtothelimit.co.uk/

What i don't know yet is how to default your old http address to now go to the secure https://revtothelimit.co.uk/

So for now you'll need to do it manually.

Open your window and instead of using the link you once had, use this instead

https://revtothelimit.co.uk/

Imagesecure by Steve Weeks, on Flickr

If it were a windows server we were running on i'd have sorted this myself, but i'm not even sure what the back end of phpBB is, so can't yet sort and am waiting for the Techies on their side to help me out with setting it to default to https

Any question, of course, ask away.
User avatar
weeksy
Site Admin
Posts: 23417
Joined: Sat Mar 14, 2020 12:08 pm
Has thanked: 5450 times
Been thanked: 13085 times

Re: Not secure address

Post by weeksy »

OK, so i've added an auto-redirect from http to https on the back end.

So i've tested myself and think it works, but would appreciate feedback if you're seeing issues.

Top left of your browser you'll have a locked padlock, which shows it's a secure SSL cert being used...
WelshDragon
Posts: 376
Joined: Sun Mar 15, 2020 12:58 pm
Location: Welsh Wales
Has thanked: 148 times
Been thanked: 54 times

Re: Not secure address

Post by WelshDragon »

Except on stupid bloody ipads that don’t show the same detail in the address line!! :roll:
Life’s for living, so let’s get on with it! :P
User avatar
MrLongbeard
Posts: 4585
Joined: Sun Mar 15, 2020 2:06 pm
Has thanked: 599 times
Been thanked: 2436 times

Re: Not secure address

Post by MrLongbeard »

Auto redirect to Https isn't happening in Chrome (windows & android.)
User avatar
Rockburner
Posts: 4375
Joined: Sun Mar 15, 2020 11:06 am
Location: Hiding in your blind spot
Has thanked: 7814 times
Been thanked: 2527 times

Re: Not secure address

Post by Rockburner »

weeksy wrote: Mon Mar 16, 2020 7:19 am Well in simple IT nerdy speak, yes, it needs 'sorting' but don't think for a second this makes anything actually 'insecure'. No-one can hack your PC etc because you've visited this site. Basically it uses what's known as a self-signed certificiate and i need to use the server information to created what's known as a CSR, send that to a certificate authority and they then send me back a digitally signed certificate which i then re-import back into the server and everything is then digitally 'signed'.

I'll get it sorted in the future, but the only thing it affects is things like entering Credit Card details on here could be classed as insecure, which i'm not intending on people doing.

The downside to this is that the cost is quite prohibitive depending on the levels we go for.

https://www.hosting.co.uk/ssl/?_ga=2.12 ... 1584124442

In work we use SSL certs of course for many applications, we send ours out to a 3rd party, but that's all sorted 'internally' so there's no actual associated costs for it... Obviously looking at this link, there's deffo a cost associated, so i need to research which level of SSL, why and then weigh up costs over requirements etc

It's on the list :)
SSL certs are free now.
Check out Cerbot. ;)
non quod, sed quomodo
User avatar
Yorick
Posts: 16736
Joined: Sat Mar 14, 2020 8:20 pm
Location: Paradise
Has thanked: 10263 times
Been thanked: 6885 times

Re: Not secure address

Post by Yorick »

MrLongbeard wrote: Mon Mar 16, 2020 3:01 pm Auto redirect to Https isn't happening in Chrome (windows & android.)
Copy and paste the new address into browser and use that.
User avatar
MrLongbeard
Posts: 4585
Joined: Sun Mar 15, 2020 2:06 pm
Has thanked: 599 times
Been thanked: 2436 times

Re: Not secure address

Post by MrLongbeard »

Yorick wrote: Mon Mar 16, 2020 3:05 pm
MrLongbeard wrote: Mon Mar 16, 2020 3:01 pm Auto redirect to Https isn't happening in Chrome (windows & android.)
Copy and paste the new address into browser and use that.
I've changed me bookmark to get it chooching.
User avatar
Bigyin
Posts: 3179
Joined: Sun Mar 15, 2020 7:39 pm
Has thanked: 1412 times
Been thanked: 2680 times

Re: Not secure address

Post by Bigyin »

The auto redirect didnt seem to work for me but opening the lin k in a new window brought it up. Bookmark changed and all tickety boo. Thanks Weeksy