Announcement

Collapse
No announcement yet.

Converting your forum to https

Collapse
X
Collapse

  • Converting your forum to https

    CONVERTING YOUR FORUM TO HTTPS
    Applies to self-hosted versions of:
    vBulletin 3; vBulletin 4; vBulletin 5;
    Cloud sites have https enabled by default and you do not need to do anything.

    This FAQ explains how to convert your vBulletin forum to use secure https (SSL) rather than http, and why you might need to.
    Note: This guide contains links to external sites. vBulletin Solutions is not responsible for the content of external links and cannot be held responsible for the accuracy of information contained on them.

    WHAT IS HTTPS?
    https stands for Hyper Text Transfer Protocol Secure. It is the secure version of http, the protocol used for sending data between your browser and a website. It means all communications between your browser and the website are encrypted. The 'S' stands for secure. Web browsers will usually display a green padlock to indicate that a secure connection is in place. For https to work, an https certificate needs to be installed on the server.

    WHAT IS AN HTTPS CERTIFICATE?
    https uses a public and private key system. Data that has been encrypted with the public key can only be decrypted by the private key and vice-versa.
    When a web browser connects to a webpage via https, the server sends its https certificate to the browser. This certificate contains the public key needed to begin the secure session.

    WHY DO I NEED HTTPS?
    Data sent over regular http connections are sent in plain text and could in theory be read by anyone who intercepts the connection. With an https connection, the data is securely encrypted, meaning that even if someone intercepted it, they wouldn't be able to read it.
    Starting in January 2017, Google's Chrome browser will begin to mark non-https pages as 'Insecure'. This warning may put off visitors to your site. Other browsers are expected to follow suit in due course.
    More details on this can be found HERE
    Additionally, Google is now using https as a ranking signal, meaning not having https could harm your site's ranking in Google. More details on this HERE.

    HOW IS THE MOBILE APP AFFECTED?
    Starting in January 2017, Apple is enforcing APP TRANSPORT SECURITY (ATS) for all new apps signed after that date. More details on this HERE. This means that apps signed after January 2017 must use secure https when making API calls and connecting to web services.
    We have updated vBulletin Mobile Suite to version 1.13 to publish apps using HTTPS, to meet Apple's App Transport Security requirement. After Jan. 1, you will not be able to submit updated apps to the iTunes App Store using earlier versions of Mobile Suite. Your current apps are fine and will continue to work with your site; you just won't be able to update them until you use v1.13.

    HOW DO I CONVERT MY FORUM TO HTTPS?
    The first thing you will need is an https certificate. In most cases, the first port of call for this will be your web host. https certificates are commonly referred to as SSL certificates, although these days they are usually actually TLS certificates. These are protocols used for https. TLS stands for Transport Socket Layer, and is the successor to SSL, which stands for Secure Socket Layer. You don't really need to concern yourself with these two protocols, but if you are interested, technical details can be found HERE.
    In most cases, your host will make a small charge for an https certificate. This is generally an annual fee which needs to be renewed. Failure to renew it will cause users to receive a warning in their browser that the certificate has expired, so it's vital to keep this up to date. https certificates are generally tied to a specific domain. The certificate will need to be installed on your server - again, generally your host will do this for you.

    You are not tied to buying the certificate from your host, however it is generally the easiest option if you're not well versed in doing this type of thing. If you purcahse one from a third party, you will normally find instructions on your web hosts website for how to perform the installation of the certificate yourself. For example, one hosting company has a guide HERE. There is another guide HERE. Use these guides at your own risk - vBulletin does not endorse and has not tested any of the guides linked to here. If you are unsure - speak to your host, who should be happy to help.

    I HAVE MY CERTIFICATE INSTALLED - WHAT NEXT?
    The next step is quite simple. Log into your vBulletin AdminCP, and then follow the appropriate instructions below for your version.

    vBulletin 3
    Go to vBulletin Options > vBulletin Options > Site Name / URL / Contact Details.
    Edit 'Forum URL' and add the 's' into the URL.
    For example, if your URL is http://www.contoso.com/forum, change it to https://www.contoso.com/forum

    Then go to Settings > vBulletin Options > vBulletin Options > Server Settings & Optimization Options > Use Remote YUI
    Set this to Google.

    vBulletin 4
    Go to Settings > Options > Site Name / URL / Contact Details.
    Edit 'Forum URL' and add the 's' into the URL.
    For example, if your URL is http://www.contoso.com/forum, change it to https://www.contoso.com/forum

    Then go to Settings > Options > Server Settings & Optimization Options > Use Remote YUI
    Set this to Google.

    vBulletin 5
    Go to vBulletin Options > vBulletin Options > Site Name / URL / Contact Details.
    Edit these three settings: 'vBulletin URL'; 'Login URL'; 'Core URL' and add the 's' into the URL.
    For example, if your URL is http://www.contoso.com/forum, change it to https://www.contoso.com/forum
    NOTE: Do not remove the word 'core' at the end of the core URL. You will break your site!

    Then go to Settings > Options > Server Settings & Optimization Options > Use Remote jQuery
    Set this to Google.

    The key to all three vBulletin versions is that all you do in the URL settings is change http to https. Do not alter any other part of the URL.

    Once you have changed these settings, go to AdminCP > Maintenance > General Update Tools, and rebuild the styles. (In vB3 this is AdminCP > Maintenance > Update Counters). Leave the default settings and just run this update tool.

    ANYTHING ELSE?
    Your site should now load and run normally when using https in the URL. However, you now need to redirect any http traffic to https, so that everyone using your site uses the secure connection.
    Again, in most cases, the simplest way to arrange this is to ask your host to configure it for you. They shouldn't charge for doing this, and it won't take them very long.
    If you'd rather do it yourself, it involves playing about with special files used by different types of server software - For instance, a server running 'Apache' will use an '.htaccess' file, whereas a server running IIS will use a 'web.config' file. If you don't know which server software your server is running, speak to your host. GoDaddy have a useful guide to making these changes HERE. However, these files can be quite tricky to work with, and an incorrect entry will break your site. It's much simpler to get your host to do it!

    THAT'S IT!
    You shouldn't encounter any difficulties and your site should be showing a green padlock in most browsers.
    You may run into issues with 'embedded images', where people have embedded external images or videos from third party sites into your posts, where those sites are or were not using https. These will trigger what is called a 'Mixed Content Warning' in the padlock area of the browser. In practice, what this means is that such embedded images or videos will not show and users may just see a blank space. You should aim to convert these images to attachments, subject to copyright, though this will be a manual task and can be fairly arduous if there are lots of them. Alternatively you can manually edit the embedded URL to change it to https. This will work for major sites like YouTube, but on some sites it may not work if https is not available. There are some third party add-ons that can help with this problem such as THIS ONE, however vBulletin cannot provide official support for third party code.

    If you have any questions regarding this guide, please post in the correct support forum for your version.
    Last edited by Mark.B; Thu 4th May '17, 12:24pm.

    • Glenn Vergara
      #5
      Glenn Vergara commented
      Editing a comment
      If you have posts that that have embedded external images that are not using https, you will get a mixed content error in the browser console and the padlock icon in the address bar will not be green. To prevent that from happening, you can block all the mixed content using this meta tag:

      Code:
      <meta http-equiv="Content-Security-Policy" content="block-all-mixed-content"/>
      That meta tag should be placed inside the <head> tag. For vB5, you can paste it in the head_include template. For vBCloud, you can utilize the Search Engine Verification option in AdminCP > Settings > Options to insert the meta tag.

      See these links for reference:
      https://developers.google.com/web/fu...-mixed-content
      https://developer.mozilla.org/en-US/...-mixed-content

    • Jairo Morillo
      #6
      Jairo Morillo commented
      Editing a comment
      can you detail more how to paste the code in head_include please vbulletin 5.3.3


      <meta http-equiv="Content-Security-Policy" content="block-all-mixed-content"/>

    • Glenn Vergara
      #7
      Glenn Vergara commented
      Editing a comment
      Login to AdminCP and go to Styles. Search for "head_include" template. Edit the ones under the active themes/styles your site is using.
    Posting comments is disabled.

About the Author

Collapse

Mark.B Find out more about Mark.B

Article Tags

Collapse

advanced (5) album bits (1) android (2) api (29) array (17) beginner (17) blog (4) calendar (2) center (1) cms (2) connect (1) customization (1) forum (3) forums (4) Intermediate (5) iphone (3) mapi (30) methods (10) mobile (34) sections (1) style (2) thread (1) threads (4) vb5howto (5) vBulletin (5)

Latest Articles

Collapse

  • Third-Party Logins: Twitter
    Wayne Luke
    You will need to use an existing twitter account in order to use this functionality.

    Create an app using your twitter account

    In your browser go to https://apps.twitter.com/app/new

    Check App Settings

    Go to the application settings (e.g. https://apps.twitter.com/app/12345/settings where 12345 references the app created in step 2. You can access the settings by going to the list of
    your apps (https://apps.twitter.com), clicking on the app link, then clicking...
    Tue 10th Apr '18, 9:00am
  • The Basic Anatomy of a vBulletin Page
    Wayne Luke
    vBulletin 5's user output is created using a system of pages that are customizable by the site administrator. This system is called Site Builder. By breaking the system down into pages, a lot of control is given to the system administrator. By using Site Builder, you can create a unique site without any knowledge of HTML or CSS.

    vBulletin's pages are created using layers built upon a grid layout. Each page starts with a layout which defines the content areas of the page. Layouts define...
    Mon 11th Sep '17, 8:55am
  • Enabling Push Notifications in vBulletin 5.3.2 and Mobile Suite 1.16
    Wayne Luke
    vBulletin Mobile Suite 1.16 includes functionality for Push Notifications. One of the requirements to add this functionality is that you must be running vBulletin 5.3.2 Connect on your site and create a project with Google's Firebase Cloud Messaging (FCM) platform. The steps below will walk you through the process of enabling this functionality in vBulletin and in your Mobile Apps.

    Add a project to your Firebase account






    Setup Push Notifications...
    Thu 27th Jul '17, 8:56am
  • Enabling Two-Factor Authentication
    Wayne Luke
    vBulletin 5.3.0 and higher will allow site owners to enable Two-Factor Authentication for Administrator and Moderator functionality. This is an extra layer of security provided to make sure your user data remains as safe as possible. Two-Factor Authentication works in conjunction with an app on the user's smartphone, tablet, or computer. These apps provide a security token that lasts a limited time before expiring. The security token is created using industry standard algorithms and a unique string...
    Tue 4th Apr '17, 8:38am
  • How to moderate the posts of new users only
    Wayne Luke
    To help combat spam, many users opt to have new user’s posts moderated until they’ve made a specific number of posts. This allows the Admin/Moderator team to keep potentially malicious posts out of the public eye until a user has effectively passed a ‘probationary period’ as a member of the site.

    In order to do this, you will need to create a custom usergroup and a promotion.

    Creating a Custom Usergroup
    First, you need to setup the usergroup for your non-Moderated...
    Wed 22nd Feb '17, 9:13am
  • Rebuilding the Sphinx index
    Wayne Luke
    From time to time, we will need to update the indexing schema for the Sphinx server. In order for this fix to take effect, you will need to update the sphinx schema for the index. Follow these steps to rebuild your Sphinx Search Schema.
    1. Stop the Sphinx service on your server.
    2. Replace your existing Sphinx configuration file (vbulletin-sphinx.php) with the one provided in the current version of vBulletin 5 Connect. You can find this file in the do_not_upload directory.
    3. Update the file as provided
    ...
    Fri 3rd Feb '17, 1:01pm
Working...
X