Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Friendly URLFriendly URL's bypassing Required SSL encryption?
Previous
 
Next
New Post
4/29/2006 2:07 AM
 

Greetings,

This problem is two fold, so I'll quick try to explain what's going on. Here's the setup.

I've installed a fresh DNN 3.2.2 into a new web site (not the Default or a virtual). Because I don't entirely trust 3rd party software solutions for maintaining SSL coverage, I've decided to turn on SSL under the web site's Directory Security tab in IIS 6.0 Manager. Because I want to allow redirection, I then turned off the SSL protection on the splash file Default.aspx and add some redirecting ASP.

The first problem I ran into was that apparently if you have the "Require SSL" option turned on at the site level, even though you might have the SSL turned off on the default content, http://soandso.com and http://soandso.com/index.html do NOT behave the same. The first will fail with a 403 error (https required) and the second will succeed.

So I thought, I'll just turn off the SSL at the site level, put the redirecting code in a separate file. Turn SSL off on this file. Then turn SSL on for all the other top-level folders and files. This way the default page isn't SSL required, but everything else should be.

Wrong again! Apparently with the Friendly URL feature turned on, SSL is totally confused and while under this setup https://soandso.org/Default.aspx?tabid=53 is secure, https://soandso.org/Blog/tabid/53/Default.aspx is still being served over unsecured channels.

Surely there's something going on that I'm missing. I can and will be turning off Friendly URL's, but something here just doesn't seem right.

Casey

 
New Post
4/30/2006 9:45 PM
 

I afraid that I cannot help you with your problems configuring IIS.  But my SSL_Module Click Here will handle what you are trying to do.  It controls which page in secure and which is unsecured based on your settings.  No involvement on IIS settings (other than installing cert) is requried.

It's been my experience that working the IIS settings are best left to experts.  However at Click for Thread there is an excellant writeup that may do what you want.

If you would like more info, you can follow the link and download a demo with a manual or contact me through the forum.

Tom


Tom Thorp
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Friendly URLFriendly URL's bypassing Required SSL encryption?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out