ssl

How do I get rid of the IE8 ssl warning message "Do you want to view only the webpage content that was delivered securely?” with ScriptManager?

A login page on our asp.net website uses https – while almost all of our other pages do not. On this login page, IE8 users receive the “Do you want to view only the webpage content that was delivered securely?” message. Many users press “Yes” out of habit which breaks our login page. I know the problem stems from the WebResource.axd a...

Tomcat6 behind Apache2.2 proxy with SSL

Hello, I use Apache 2.2 with SSL as proxy(mod_jk). Behind it running tomcat6(without SSL) . When I use http connection everything work ok eg. for tomcat manager "http://localhost/manager/html", but when I try "https://localhost/manager/html" I get "The requested URL /manager/html was not found on this server" message . Should I add somet...

My IIS server won't serve SSL sites to some browsers

(This is cross-posted at http://serverfault.com/questions/164625/my-iis-server-wont-serve-ssl-sites-to-some-browsers, which is the more appropriate place, but StackOverflow gets so much more traffic that I had to put it here as well.) I've got an IIS 6.0 server that won't serve pages over SSL to some browsers. In Webkit-based browsers o...

reCAPTCHA (Zend_Service_ReCaptcha) throws "Unable to Connect to tcp://api-verify.recaptcha.net:80"

Hi, I am using reCAPTCHA on this page but when I submit I get following error in my apache log: This started happening after I set ssl to true (i have to use it, becouse website is SSL) [Wed Jul 28 18:47:54 2010] [error] [client X.X.31.80] PHP Fatal error: Uncaught exception 'Zend_Http_Client_Adapter_Exception' with message 'Unable to...

Two domains, one site, one SSL checkout. How to get cookies?

Hi, There is a multilingual web shop, visitors can access from two domains, with different language: hxxp://x.com - English hxxp://x.ru - Russian, which is an add-on domain to x.com. The authentication and cart pages are here, through SSL: https://x.com/index.php?mode=login How can I use the cookie informations of x.ru on hxxps://x.co...

is RapidSSL wildcard cert supported by major browsers?

I'm thinking of buying a wildcard SSL cert from clickSSL : http://www.clickssl.com/rapidssl/rapidsslwildcard.aspx That would be a rapidssl certificate, and I was looking into my firefox options to see if RapidSSL is in the list of recognized Authorities. My certificate manager doesn't mention RapidSSL anywhere. Am I looking for the w...

How do I get paster serve to serve both HTTP and HTTPS requests at the same time?

For now I have the following lines in a project configuration on pylons: [server:main] ... ssl_pem = /path-to-pem/file-name.pem so paster serves only HTTPS requests but not HTTP. Any HTTP request causes the following exception in paster debug console: Traceback (most recent call last): File "/home/eigenein/Projects/Python/Pylons/li...

Mutual authentication SOAP error

My apologies if this has limited information. I'll add more info if somebody asks for it. I'm just not sure what to give you. I'm making a SOAP call to a 3rd party. They require mutual authentication. This means their servers send an SSL cert to me. I send one to them. Then in the SOAP message there's another cert. Given that in the co...

Skip SSL Check in Zend_HTTP_Client

All, I am using Zend_HTTP_Client to send HTTP requests to a server and get response back. The server which I am sending the requests to is an HTTPS web server. Currently, one round trip request takes around 10-12 seconds. I understand the overhead might be because of the slow processing of the web server to which the requests go. Is i...

how to a website SSL certificate is valid or not?

Hi, I got an issue from my client regarding the SSL setup for his website. I'm not familiar with the SSL certification setup process. He is saying that We have an SSL certificate for this server but I can’t tell if it’s setup properly or not. If I open that website, firefox says Warning: Contains unauthorized content. I am seeing some ...

DNS Record / SSL / redirect

Note: migrated to: http://serverfault.com/questions/165570/dns-record-ssl-redirect Hi there, I wonder if anyone is able to point me in the right direction? We want to setup a sub domain on our server which points to an IP of a second server which is providing some checkout functionality for us. So when a customer types sub-doma...

compiling cURL with SSL support - Fedora 11

Hi All! I'm new to Linux/Fedora (and I'm using Fedora 11 because I need PHP 5.2 and don't know how to "downgrade" on later versions of the OS) so keep that in mind while you read. I'm currently trying to enable cURL on my Fedora 11 install in order to use an NTLM authentication payment gateway from my machine. I've seen it work on box...

How should I skim money off a transaction between 2 people on my site?

This is sort of not relevant to programming but I think it also is: MY site is being built around people selling products through the site and customers buying the product through it. I'll then shave a % off the top of the sale. As far as skimming a % of the sale off the top, what is the order of events that should take place to do tha...

HTTPS vs HTTP and livehttpheaders

I realize that HTTPS is supposed to be more secure because it encrypts communication between you and the server so that your passwords and credit card numbers don't get sent in plain-text. However, when using LiveHTTPHeaders, I can still see my password in plain-text in the POST even when using an https connection. Why is this the case...

Apache Virtual Host settings with hostnames

I am using apache as my front http server which handles requests for JBoss 4.2.2 running as an application server.I have a J2EE application running on JBoss handles mutliple sites requests. My IP is registered to xyz.com a request to community1.xyz.com loads site for community1 a request to community2.xyz.com loads site for community2...

Iphone libcurl WITH SSL enabled..?

Has anyone had any luck building libCurl WITH SSL (openSSL) enabled for the Iphone...? If so, could you recommend the versions you used and your cmd line config / build options...? Preferably Non-Xcode answers... Thanks! ...

WCF Over SSL Uses Machine Name IIS 7.5

I am having trouble setting up SSL with my WCF on IIS 7.5. I have seen this post: http://stackoverflow.com/questions/470111/wcf-not-using-my-domain-name-but-rather-my-computer-name-when-viewing-myservice However, the solution for IIS 7 does not seem to be working for me. In addition, I have a wildcard ssl, I'm not sure if that makes ...

Why does nginx reverse proxy of ssl to apache causes endless redirects?

I have set up nginx to handle SSL requests and send them to Apache/mod_python as described in http://code.google.com/p/mango-py/wiki/SSLRedirect. I added the django Middleware. I do proxy_set_header in nginx as described in http://yuji.wordpress.com/2008/08/15/django-nginx-making-ssl-work-on-django-behind-a-reverse-proxy/. This is intend...

Secure ODBC network connection to an MS Access database

Pardon my outrageous silliness, I don't know if this is even possible. Here's the situation. There is an MS Access "database" (yes, I know, believe me, I know) which I'll need to SELECT, UPDATE and INSERT to from a remote location. The catch is that this needs to happen securely. I have complete control over the remote machine which h...

How do I prevent un-encrypted report manager connections?

Hi, I am installing SSRS 2008 currently and am trying to ensure that all reports are delivered encrypted, via the certificate we have on the server. I have the default config for SSRS after installation and have added the certificate to Report Server and Report Manager. I can now access https://server/reportserver_instance and https://se...