Apache Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationApache Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old February 8th, 2013, 04:26 PM
qwertyjjj qwertyjjj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2010
Posts: 75 qwertyjjj User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 15 h 7 m 39 sec
Reputation Power: 4
SSL cert on same domain?!

My host company Servage seem to say that they cannot host a SSL certificate on the same domain.
For example if you have a site www.mysite.com, the SSL cannot also be active for www.mysite.com...something to do with the DNS.
They say I have to have http on http://www.mysite.com and https on https://mysite.com

WTF!

Almost every site on the internet has SSL for the same domain that it is operating on doesn't it?

Last edited by qwertyjjj : February 8th, 2013 at 04:34 PM.

Reply With Quote
  #2  
Old February 8th, 2013, 05:38 PM
E-Oreo's Avatar
E-Oreo E-Oreo is offline
Lost in code
Click here for more information.
 
Join Date: Dec 2004
Posts: 7,931 E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)  Folding Points: 945 Folding Title: Novice Folder
Time spent in forums: 2 Months 7 h 43 m 47 sec
Reputation Power: 7053
Technically www.mysite.com and mysite.com are not the same domain. Usually only very large websites have certificates on both. Until recently, even Amazon did not have a valid certificate on both.

If you want to have HTTPS at both addresses, you can either buy a separate certificate for each, or you can buy a wildcard certificate that covers both. Your host is correct that a normal single domain certificate will not work for both. That is by design, and there's nothing the host can do about it.
__________________
PHP FAQ
How to program a basic, secure login system using PHP

Quote:
Originally Posted by Spad
Ah USB, the only rectangular connector where you have to make 3 attempts before you get it the right way around

Reply With Quote
  #3  
Old February 8th, 2013, 06:05 PM
requinix's Avatar
requinix requinix is offline
Still alive
Click here for more information.
 
Join Date: Mar 2007
Location: Washington, USA
Posts: 12,690 requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)requinix User rank is General 120th Grade (Above 100000 Reputation Level)  Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1Folding Points: 417516 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 5 Months 1 Week 4 Days 3 h 43 m 37 sec
Reputation Power: 8969
Send a message via AIM to requinix Send a message via MSN to requinix Send a message via Yahoo to requinix Send a message via Google Talk to requinix
They weren't saying that www.yoursite.com cannot be both HTTP and HTTPS. It totally can. They were saying that www.yoursite.com and yoursite.com (no "www") cannot - at least not with the same certificate.

Reply With Quote
  #4  
Old February 9th, 2013, 03:44 AM
qwertyjjj qwertyjjj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2010
Posts: 75 qwertyjjj User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 15 h 7 m 39 sec
Reputation Power: 4
Quote:
Originally Posted by requinix
They weren't saying that www.yoursite.com cannot be both HTTP and HTTPS. It totally can. They were saying that www.yoursite.com and yoursite.com (no "www") cannot - at least not with the same certificate.


The problem seems to be this in the DNS they have
*.mysite.com A pointing to 71.xx.xx.xxx
mysite.com A pointing to 71.xx.xx.xxx
www.mysite.com A pointing to 78.xx.xx.xxx

The www now has the SSL cert, which is why it points to a different IP.

So, doesn't this mess up my site? If a user goes to http:www.mysite.com
it's going to pick up the wrong DNS entry?

Reply With Quote
  #5  
Old February 9th, 2013, 09:31 AM
E-Oreo's Avatar
E-Oreo E-Oreo is offline
Lost in code
Click here for more information.
 
Join Date: Dec 2004
Posts: 7,931 E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)  Folding Points: 945 Folding Title: Novice Folder
Time spent in forums: 2 Months 7 h 43 m 47 sec
Reputation Power: 7053
If a user goes to www.mysite.com it's going to send the request to the IP 78.xx.xx.xxx. Whether that's wrong or messes up your site isn't something I can answer. If your site is working correctly, then it's not wrong. If your site isn't working correctly, then it might be wrong.

Reply With Quote
  #6  
Old February 9th, 2013, 10:30 AM
qwertyjjj qwertyjjj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2010
Posts: 75 qwertyjjj User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 15 h 7 m 39 sec
Reputation Power: 4
Quote:
Originally Posted by E-Oreo
If a user goes to www.mysite.com it's going to send the request to the IP 78.xx.xx.xxx. Whether that's wrong or messes up your site isn't something I can answer. If your site is working correctly, then it's not wrong. If your site isn't working correctly, then it might be wrong.


the 78 is the shared SSL. In other words, I will not be able to access my site on http://www.mydomain.com because the dns will never pick it up.

Reply With Quote
  #7  
Old February 9th, 2013, 12:03 PM
E-Oreo's Avatar
E-Oreo E-Oreo is offline
Lost in code
Click here for more information.
 
Join Date: Dec 2004
Posts: 7,931 E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)  Folding Points: 945 Folding Title: Novice Folder
Time spent in forums: 2 Months 7 h 43 m 47 sec
Reputation Power: 7053
You can't have separate DNS entries for HTTP and HTTPS. DNS only operates at the domain name level, it can't deal with ports or services at all.

A web server that is configured to serve HTTPS traffic is nearly always configured to serve HTTP traffic too.

Given the way your DNS records are set up, I would expect 78.xx.xx.xxx and 71.xx.xx.xxx to be the same physical server. I would also expect http://mysite.com/, http://www.mysite.com/ and https://www.mysite.com/ to all serve the same content. The first would resolve to the 71 address, and the latter two would resolve to the 78 address.

However, the fact that you say "shared" SSL is a potential red flag. When a host refers to SSL as being "shared" it means there are some caveats to the way the system is set up that make it not operate like a standard SSL setup. Often the caveat is that you have to access the secured site over the host's domain name (so that you don't have to buy your own certificate), although there is no official technical definition of "shared" SSL so it could mean whatever the host wants it to mean.

What actually happens right now when you try to visit http://www.mydomain.com/? Do you get a 404 page? Does the connection time out?

Reply With Quote
  #8  
Old February 10th, 2013, 05:43 AM
qwertyjjj qwertyjjj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2010
Posts: 75 qwertyjjj User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 15 h 7 m 39 sec
Reputation Power: 4
Quote:
Originally Posted by E-Oreo
You can't have separate DNS entries for HTTP and HTTPS. DNS only operates at the domain name level, it can't deal with ports or services at all.

A web server that is configured to serve HTTPS traffic is nearly always configured to serve HTTP traffic too.

Given the way your DNS records are set up, I would expect 78.xx.xx.xxx and 71.xx.xx.xxx to be the same physical server. I would also expect http://mysite.com/, http://www.mysite.com/ and https://www.mysite.com/ to all serve the same content. The first would resolve to the 71 address, and the latter two would resolve to the 78 address.

However, the fact that you say "shared" SSL is a potential red flag. When a host refers to SSL as being "shared" it means there are some caveats to the way the system is set up that make it not operate like a standard SSL setup. Often the caveat is that you have to access the secured site over the host's domain name (so that you don't have to buy your own certificate), although there is no official technical definition of "shared" SSL so it could mean whatever the host wants it to mean.

What actually happens right now when you try to visit http://www.mydomain.com/? Do you get a 404 page? Does the connection time out?


I get a "the server is redirecting in a way that cannot complete" error.
Some kind of loop that wordpress must be doing to do with sessions or other.

Reply With Quote
  #9  
Old February 10th, 2013, 09:29 AM
E-Oreo's Avatar
E-Oreo E-Oreo is offline
Lost in code
Click here for more information.
 
Join Date: Dec 2004
Posts: 7,931 E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)  Folding Points: 945 Folding Title: Novice Folder
Time spent in forums: 2 Months 7 h 43 m 47 sec
Reputation Power: 7053
Try testing it with just a plain .html file so you can rule out or rule in problems with WordPress. But yes, I agree that it's probably a problem with WordPress.

Reply With Quote
  #10  
Old February 10th, 2013, 12:17 PM
qwertyjjj qwertyjjj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2010
Posts: 75 qwertyjjj User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 15 h 7 m 39 sec
Reputation Power: 4
What is the correct way to setup the DNS so that
http://www.mysite.com goes to IP 71.xx.xx.xxx
and https://www.mysite.com go to IP 78.xx.xx.xxx

current dns:
*.mysite.com A pointing to 71.xx.xx.xxx
mysite.com A pointing to 71.xx.xx.xxx
www.mysite.com A pointing to 78.xx.xx.xxx

Reply With Quote
  #11  
Old February 10th, 2013, 02:49 PM
E-Oreo's Avatar
E-Oreo E-Oreo is offline
Lost in code
Click here for more information.
 
Join Date: Dec 2004
Posts: 7,931 E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)  Folding Points: 945 Folding Title: Novice Folder
Time spent in forums: 2 Months 7 h 43 m 47 sec
Reputation Power: 7053
Quote:
What is the correct way to setup the DNS so that
http://www.mysite.com goes to IP 71.xx.xx.xxx
and https://www.mysite.com go to IP 78.xx.xx.xxx

It is impossible to do that. There is no way to configure DNS so that HTTP goes to one IP and HTTPS goes to a different IP.

Reply With Quote
  #12  
Old February 11th, 2013, 03:18 AM
qwertyjjj qwertyjjj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2010
Posts: 75 qwertyjjj User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 15 h 7 m 39 sec
Reputation Power: 4
Quote:
Originally Posted by E-Oreo
It is impossible to do that. There is no way to configure DNS so that HTTP goes to one IP and HTTPS goes to a different IP.


But this is how the hosting company propose to setup the DNS.
Perhaps the SSL goes through reverse proxy type setup?

Reply With Quote
  #13  
Old April 3rd, 2013, 01:51 AM
Davis Joseph Davis Joseph is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2012
Posts: 27 Davis Joseph User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 30 m 57 sec
Reputation Power: 0
Quote:
Originally Posted by E-Oreo
Technically www.mysite.com and mysite.com are not the same domain. Usually only very large websites have certificates on both. Until recently, even Amazon did not have a valid certificate on both.
If you want to have HTTPS at both addresses, you can either buy a separate certificate for each, or you can buy a wildcard certificate that covers both. Your host is correct that a normal single domain certificate will not work for both. That is by design, and there's nothing the host can do about it.


I do agree with E-Oreo that mysite.com and www.mysite.com are totally different. But that does not mean you have to buy Wildcard SSL or multi domain SSL, You simply buy domain ssl certificate from GeoTrust and RapidSSL, bear in mind buy ssl for www.mysite.com not for mysite.com

Dedicated IP address is required to secure your www.mysite.com and mysite.com with rapidssl certificate or geotrust quickssl premium certificate. So you need same IP address for those both domain names like
Mysite.com: 71.xx.xx.xxx
www.mysite.com: 71.xx.xx.xxx
__________________
SSLMatrix - Leading SSL Certificate provider.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationApache Development > SSL cert on same domain?!

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap