Difference between revisions of "X-Cart:Configuring HTTPS"

From X-Cart 4 Classic
Jump to: navigation, search
 
(25 intermediate revisions by 6 users not shown)
Line 1: Line 1:
'''Firstly''', you should obtain an SSL certificate and have it properly installed and configured on your web server.
+
This article provides guidelines for configuring HTTPS for your X-Cart store.
  
The majority of hosting companies help their customers to purchase SSL certificates or provide their own Shared SSL URLs. If your hosting company doesn't render such services, you will need to purchase a certificate on your own.
+
==Obtain an SSL certificate==
  
We will be glad to assist you with this issue. You can purchase SSL certificates from our company. We sell SSL certificates provided by the world's leading Certification Authority, Comodo Group http://www.comodogroup.com. For details, conditions and prices, please see http://www.x-cart.com/ssl_certificates.html.
+
To use HTTPS for your X-Cart store site, you need to obtain an SSL certificate and have it properly installed and configured on your web server. You also need to monitor your SSL certificate expiration date and be ready to renew it when necessary.  
  
If you are on a dedicated server, we can offer you our service on analyzing and configuring your server and/or install the SSL Certificate on it. Please note: we will need the 'root' access to your server over SSH or the 'Administrator' access over MS Remote Access Desktop to complete these tasks.
+
The majority of hosting companies help their customers to purchase SSL certificates or provide their own Shared SSL URLs. If your hosting company does not render such services, you will need to purchase a certificate on your own.
  
'''Secondly''', once you have the SSL certificate installed and configured, you should configure the HTTPS server in X-Cart. To do it, modify the <xcart_dir>/config.php file and set the $xcart_https_host variable properly:
+
We will be glad to assist you with this issue. You can purchase SSL certificates from our company. We sell SSL certificates provided by the world's leading Certification Authority, [https://www.comodogroup.com Comodo Group]. For details, conditions and prices, please see https://www.x-cart.com/ssl/.
  
<pre>
+
If you are on a dedicated server, we can offer you our service on analyzing and configuring your server and/or install an SSL Certificate on it. Please note that we will need the 'root' access to your server over SSH or the 'Administrator' access over MS Remote Access Desktop to complete these tasks.
/**
 
* X-Cart HTTP & HTTPS host and web directory
 
*
 
* This section defines the location of your X-Cart installation. If X-Cart is
 
* installed using Web installation, the variables of this section are
 
* configured via the Installation Wizard. If you install X-Cart manually, use
 
* this section to provide your web server details manually.
 
*
 
* $xcart_http_host - Host name of the server on which your X-Cart software is
 
* to be installed;
 
* $xcart_https_host - Host name of the secure server that will provide access
 
* to your X-Cart-based store via the HTTPS protocol;
 
* $xcart_web_dir - X-Cart web directory.
 
*
 
* NOTE:
 
* The variables $xcart_http_host and $xcart_https_host must contain hostnames
 
* ONLY (no http:// or https:// prefixes, no trailing slashes).
 
*
 
* Web dir is the directory where your X-Cart is installed as seen from the Web,
 
* not the file system.
 
*
 
* Web dir must start with a slash and have no slash at the end. An exception to
 
* this rule is when you install X-Cart in the site root, in which case you need
 
* to leave the variable empty.
 
*
 
* EXAMPLE 1:
 
* $xcart_http_host ="www.yourhost.com";
 
* $xcart_https_host ="www.securedirectories.com/yourhost.com";
 
* $xcart_web_dir ="/xcart";
 
* will result in the following URLs:
 
* http://www.yourhost.com/xcart
 
* https://www.securedirectories.com/yourhost.com/xcart
 
*
 
* EXAMPLE 2:
 
* $xcart_http_host ="www.yourhost.com";
 
* $xcart_https_host ="www.yourhost.com";
 
* $xcart_web_dir ="";
 
* will result in the following URLs:
 
* http://www.yourhost.com/
 
* https://www.yourhost.com/
 
*/
 
</pre>
 
  
'''Thirdly''', if you are going to use a secure server, copy the entire X-Cart directory to the HTTPS location (or the secure server if it is different from the HTTP server), then delete all the files and directories from directory <xcart_dir>/var/templates_c at the HTTPS location. In case both the HTTP and HTTPS sites are located on the same Unix server, you can simply create a symbolic link from the HTTPS location to the HTTP location of X-Cart. Contact your hosting administrators to find out whether that's the case for your account.
+
==Configure the HTTPS server in X-Cart==
  
'''Finally''', enable the secure checkout at your store by selecting the HTTPS protocol for the payment methods to be secure on the Payment Methods page. You can also adjust these HTTPS options on the Security page in the Settings:
+
Once you have an SSL certificate for your store site installed and configured, you should adjust the HTTPS server settings in X-Cart. If your HTTPS host differs from your HTTP host, you will need to edit the file <xcart_dir>/config.php specifying your HTTPS host in the variable $xcart_https_host.
  
* "Use HTTPS for users' login and registration" ("General settings").
+
==Enable HTTPS for your store==
* "Use secure login form on a separate page (HTTPS)" ("General settings").
 
  
'''Optionally''', if you need secure certain php scripts you should add https scripts to <xcart_dir>/https.php file, 'https_scripts' array. You can find some examples in <xcart_dir>/https.php file:
+
<div id="https_for_all_pages"> </div>
 +
===Enable HTTPS for the entire X-Cart store site===
  
<pre>
+
====Method 1. Use for web servers with support for .htaccess, like apache====
$https_scripts[] = 'login.php';
+
<div class="mw-collapsible">
$https_scripts[] = array(
+
If you are using a web server of the above-named type, to set your entire X-Cart store to operate over HTTPS, you should add the following code to the .htaccess file after the line "RewriteBase":
'cart.php',
+
<nowiki>
"mode=checkout",
+
RewriteCond %{HTTPS} off
);
+
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]  
</pre>
+
</nowiki>
 +
If the canonical URL of your site is known, it will be even better to add the rules as follows:
 +
<nowiki>
 +
RewriteCond %{HTTPS} off
 +
RewriteRule ^(.*)$ https://example.com/$1 [^] [R=301,L]
 +
</nowiki>
 +
(Be sure to replace "example.com" with your actual canonical URL).
 +
The above code should be added ''before'' the code for handling Clean URLs.
 +
 
 +
You can also use the following instructions:
 +
https://www.sslshopper.com/apache-redirect-http-to-https.html
 +
</div>
 +
<br />
 +
Enable the 'Use secure protocol (HTTPS)' option for X-Cart versions 4.7.9 and later.
 +
 
 +
 
 +
====Method 2. Use for servers like nginx.conf====
 +
<div class="mw-collapsible">
 +
Convert the rules cited in Method 1 above
 +
to nginx.conf
 +
as follows:
 +
<nowiki>
 +
server {
 +
    listen 80 default_server;
 +
    listen [::]:80 default_server;
 +
    server_name _;
 +
    return 301 https://$host$request_uri;
 +
}
 +
</nowiki>
 +
For more info, see:
 +
https://www.bjornjohansen.no/redirect-to-https-with-nginx
 +
</div>
 +
<br />
  
'''Optionally''', if you want to switch the whole x-cart to secure mode edit https.php file. Find the line
+
Enable the 'Use secure protocol (HTTPS)' option for X-Cart versions 4.7.9 and later.
 +
<br /><br />
 +
====Method 3. Use in addition to Methods 1 or 2 above or as a standalone method if Methods 1 or 2 cannot be used====
 +
<div class="mw-collapsible">
 +
'''X-Cart versions 4.7.9 and later:'''<br />
 +
To switch your entire X-Cart store to HTTPS:
 +
# In your X-Cart store's Admin area, go to the '<u>General settings/Security options</u>' page and scroll down to the '''HTTPS options''' section.
 +
# Enable the 'Use secure protocol (HTTPS)' option:<br />[[File:xc4_use_secure_protocol_479nlater.png|border|700px]]
 +
# Save the changes.
  
<pre>
+
'''X-Cart versions prior to 4.7.9:'''<br />
 +
To switch your entire X-Cart store to HTTPS, edit the file https.php.
 +
Find the line:
 +
<nowiki>
 
function is_https_link($link, $https_scripts) {
 
function is_https_link($link, $https_scripts) {
</pre>
+
</nowiki>
 
 
 
and replace it with
 
and replace it with
 
+
<nowiki>
<pre>
 
 
function is_https_link($link, $https_scripts) {
 
function is_https_link($link, $https_scripts) {
 
return true;
 
return true;
</pre>
+
</nowiki>
So, that the code:
+
</div>
<pre>return true;</pre> is added at the very beginning of the "is_https_link" function declaration.
+
 
 +
===Enable HTTPS for the login, registration, checkout and payment pages (X-Cart versions prior to 4.7.9)===
 +
If you do not wish to enable HTTPS for the entire store site but need HTTPS for the login, registration, checkout and payment pages:
 +
# In your X-Cart store's Admin area, go to the '<u>General settings/Security options</u>' page and scroll down to the '''HTTPS options''' section.
 +
# Enable the 'Use secure protocol (HTTPS)  for login, registration, checkout and payment pages' option:<br />[[File:xc4_use_secure_protocol_before479.png|border|700px]]
 +
# If you wish, enable the following HTTPS options on the same page:
 +
#* [[X-Cart:Security_Options#HTTPS_options | Use HTTPS for users' login and registration]]
 +
#* [[X-Cart:Security_Options#HTTPS_options | Use secure login form on a separate page (HTTPS)]] (Available in X-Cart versions 4.5.4 and earlier. Removed in X-Cart 4.5.5)
 +
# Save the changes.
 +
# If using X-Cart 4.5.4 or earlier, go to the Payment Methods configuration page and specify which payment methods should work using the HTTPS protocol. Save the changes.
 +
 
 +
===Enable HTTPS for specific php scripts===
 +
If you do not wish to enable HTTPS for the entire store site but just need to secure some php scripts in your X-Cart store so they can only be accessed via HTTPS, you should add the scripts that need to be secured to the 'https_scripts' array in the file <xcart_dir>/https.php. You can find some examples of how that can be done right in the file <xcart_dir>/https.php:
 +
 
 +
<nowiki>
 +
$https_scripts[] = 'login.php';
 +
$https_scripts[] = array(
 +
'cart.php',
 +
"mode=checkout",
 +
);
 +
</nowiki>
  
'''Now''', if your web server does not use SSL certificates, and you are running an HTTPS Proxy instead, you may need to make additional settings to enable your X-Cart work over SSL (secure connection). In the include/https_detect.php file, define the proxy IP address and set the $HTTPS variable to 'true':
+
==HTTPS Proxy==
 +
If your web server does not use SSL certificates, and you are running an HTTPS Proxy instead, you may need to configure some additional settings to enable your X-Cart work over SSL (secure connection). In the file include/https_detect.php, specify the proxy IP address and set the $HTTPS variable to 'true':
  
<pre>
+
<nowiki>
 
if ($_SERVER['REMOTE_ADDR'] == '192.160.1.1') {
 
if ($_SERVER['REMOTE_ADDR'] == '192.160.1.1') {
 
$HTTPS_RELAY = true;
 
$HTTPS_RELAY = true;
 
$HTTPS = true;
 
$HTTPS = true;
 
}
 
}
</pre>
+
</nowiki>
  
 
If you are not sure whether your web server uses SSL certificates or runs behind an HTTPS Proxy, contact your hosting service provider or server administrator or email our technical support - we will help you find that out.
 
If you are not sure whether your web server uses SSL certificates or runs behind an HTTPS Proxy, contact your hosting service provider or server administrator or email our technical support - we will help you find that out.
  
[[Category:X-Cart user manual]]
+
==Troubleshooting==
 +
 
 +
If you experience problems with external services (payment / shipping) working over https while using curl/libcurl as the https module, try adding the following line to <u>top.inc.php</u>:
 +
 
 +
<nowiki>
 +
define('USE_CURLOPT_SSL_VERIFYPEER', 1);
 +
</nowiki>
 +
 
 +
after
 +
 
 +
<nowiki>
 +
$xcart_dir = rtrim(realpath($xcart_dir), XC_DS);
 +
</nowiki>
 +
<br /><br />
 +
 
  
 
[[Category:X-Cart user manual]]
 
[[Category:X-Cart user manual]]

Latest revision as of 17:41, 22 July 2020

This article provides guidelines for configuring HTTPS for your X-Cart store.

Obtain an SSL certificate

To use HTTPS for your X-Cart store site, you need to obtain an SSL certificate and have it properly installed and configured on your web server. You also need to monitor your SSL certificate expiration date and be ready to renew it when necessary.

The majority of hosting companies help their customers to purchase SSL certificates or provide their own Shared SSL URLs. If your hosting company does not render such services, you will need to purchase a certificate on your own.

We will be glad to assist you with this issue. You can purchase SSL certificates from our company. We sell SSL certificates provided by the world's leading Certification Authority, Comodo Group. For details, conditions and prices, please see https://www.x-cart.com/ssl/.

If you are on a dedicated server, we can offer you our service on analyzing and configuring your server and/or install an SSL Certificate on it. Please note that we will need the 'root' access to your server over SSH or the 'Administrator' access over MS Remote Access Desktop to complete these tasks.

Configure the HTTPS server in X-Cart

Once you have an SSL certificate for your store site installed and configured, you should adjust the HTTPS server settings in X-Cart. If your HTTPS host differs from your HTTP host, you will need to edit the file <xcart_dir>/config.php specifying your HTTPS host in the variable $xcart_https_host.

Enable HTTPS for your store

Enable HTTPS for the entire X-Cart store site

Method 1. Use for web servers with support for .htaccess, like apache

If you are using a web server of the above-named type, to set your entire X-Cart store to operate over HTTPS, you should add the following code to the .htaccess file after the line "RewriteBase":

RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L] 

If the canonical URL of your site is known, it will be even better to add the rules as follows:

RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://example.com/$1 [^] [R=301,L]

(Be sure to replace "example.com" with your actual canonical URL). The above code should be added before the code for handling Clean URLs.

You can also use the following instructions: https://www.sslshopper.com/apache-redirect-http-to-https.html


Enable the 'Use secure protocol (HTTPS)' option for X-Cart versions 4.7.9 and later.


Method 2. Use for servers like nginx.conf

Convert the rules cited in Method 1 above to nginx.conf as follows:

server {
    listen 80 default_server;
    listen [::]:80 default_server;
    server_name _;
    return 301 https://$host$request_uri;
}

For more info, see: https://www.bjornjohansen.no/redirect-to-https-with-nginx


Enable the 'Use secure protocol (HTTPS)' option for X-Cart versions 4.7.9 and later.

Method 3. Use in addition to Methods 1 or 2 above or as a standalone method if Methods 1 or 2 cannot be used

X-Cart versions 4.7.9 and later:
To switch your entire X-Cart store to HTTPS:

  1. In your X-Cart store's Admin area, go to the 'General settings/Security options' page and scroll down to the HTTPS options section.
  2. Enable the 'Use secure protocol (HTTPS)' option:
    Xc4 use secure protocol 479nlater.png
  3. Save the changes.

X-Cart versions prior to 4.7.9:
To switch your entire X-Cart store to HTTPS, edit the file https.php. Find the line:

function is_https_link($link, $https_scripts) {

and replace it with

function is_https_link($link, $https_scripts) {
return true;

Enable HTTPS for the login, registration, checkout and payment pages (X-Cart versions prior to 4.7.9)

If you do not wish to enable HTTPS for the entire store site but need HTTPS for the login, registration, checkout and payment pages:

  1. In your X-Cart store's Admin area, go to the 'General settings/Security options' page and scroll down to the HTTPS options section.
  2. Enable the 'Use secure protocol (HTTPS) for login, registration, checkout and payment pages' option:
    Xc4 use secure protocol before479.png
  3. If you wish, enable the following HTTPS options on the same page:
  4. Save the changes.
  5. If using X-Cart 4.5.4 or earlier, go to the Payment Methods configuration page and specify which payment methods should work using the HTTPS protocol. Save the changes.

Enable HTTPS for specific php scripts

If you do not wish to enable HTTPS for the entire store site but just need to secure some php scripts in your X-Cart store so they can only be accessed via HTTPS, you should add the scripts that need to be secured to the 'https_scripts' array in the file <xcart_dir>/https.php. You can find some examples of how that can be done right in the file <xcart_dir>/https.php:

$https_scripts[] = 'login.php';
$https_scripts[] = array(
'cart.php',
"mode=checkout",
);

HTTPS Proxy

If your web server does not use SSL certificates, and you are running an HTTPS Proxy instead, you may need to configure some additional settings to enable your X-Cart work over SSL (secure connection). In the file include/https_detect.php, specify the proxy IP address and set the $HTTPS variable to 'true':

if ($_SERVER['REMOTE_ADDR'] == '192.160.1.1') {
$HTTPS_RELAY = true;
$HTTPS = true;
}

If you are not sure whether your web server uses SSL certificates or runs behind an HTTPS Proxy, contact your hosting service provider or server administrator or email our technical support - we will help you find that out.

Troubleshooting

If you experience problems with external services (payment / shipping) working over https while using curl/libcurl as the https module, try adding the following line to top.inc.php:

define('USE_CURLOPT_SSL_VERIFYPEER', 1);

after

 
$xcart_dir = rtrim(realpath($xcart_dir), XC_DS);