Solved

SSL, what is "allowed?

Posted on 2011-03-10
2
210 Views
Last Modified: 2012-05-11
So,

I have a main domain, ex. domain.com
And a subdomain, ex. secure.domain.com

I plan to add SSL to secure.domain.com

The frontpage of the subdomain will use the same layout and styling as the main domain (domain.com) and I would like to use the same css files as the main domain. The rest of the subdomain will use a seperate/new layout, so thats no problem.

The problem is, someone told me that all files in include (images, css, files outside public_html etc... everything), needs to be placed within the subdomain (for SSL). Is this true? Do I have to copy all my css, images and other files from my main domain to my subdomain?
0
Comment
Question by:kgp43
2 Comments
 
LVL 19

Expert Comment

by:Michael701
ID: 35101776
What I've done in the past is to place the secure scripts (php) in a folder under the host root. So the url would be https://www.mysite.com/secure/login.php. You can then make sure that when a script is run it's under the HTTPS:// url

This way the entire site can be viewed under the ssl.

This gets away from the warning messages when accessing files outside of the SSL domain.
0
 
LVL 30

Accepted Solution

by:
Brad Howe earned 500 total points
ID: 35101815
Hi,

CSS, Images and other files should use a relative path in the first place like ..\file.gif or ..\..\image.png. With that said, Anything that is posted in a browser under https (is secure and encrypted).

Now, the domain you want to secure is secure.domain.com. Assuming you are creating a brand new virtual host setup in your httpd.conf and simply creating virtual paths to your css/images, it will be secure.

Remember it is the site that is secure and everything under it. If the virtual host is only listening on port 443, then everything under it - not matter where the content is stored, is secure and served under SSL.

Cheers,
Hades666
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DNS @ Naked Domain Record 5 61
Form Processing in PHP 11 30
A form to still have contents even if some are wrong 10 43
PHP: concatenate query 12 30
If you are a web developer, you would be aware of the <iframe> tag in HTML. The <iframe> stands for inline frame and is used to embed another document within the current HTML document. The embedded document could be even another website.
These days socially coordinated efforts have turned into a critical requirement for enterprises.
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now