Announcement

Collapse
No announcement yet.

Converting your forum to https

Collapse
X
Collapse

  • Converting your forum to https

    CONVERTING YOUR FORUM TO HTTPS
    Applies to self-hosted versions of:
    vBulletin 3; vBulletin 4; vBulletin 5;
    Cloud sites have https enabled by default and you do not need to do anything.

    This FAQ explains how to convert your vBulletin forum to use secure https (SSL) rather than http, and why you might need to.
    Note: This guide contains links to external sites. vBulletin Solutions is not responsible for the content of external links and cannot be held responsible for the accuracy of information contained on them.

    WHAT IS HTTPS?
    https stands for Hyper Text Transfer Protocol Secure. It is the secure version of http, the protocol used for sending data between your browser and a website. It means all communications between your browser and the website are encrypted. The 'S' stands for secure. Web browsers will usually display a green padlock to indicate that a secure connection is in place. For https to work, an https certificate needs to be installed on the server.

    WHAT IS AN HTTPS CERTIFICATE?
    https uses a public and private key system. Data that has been encrypted with the public key can only be decrypted by the private key and vice-versa.
    When a web browser connects to a webpage via https, the server sends its https certificate to the browser. This certificate contains the public key needed to begin the secure session.

    WHY DO I NEED HTTPS?
    Data sent over regular http connections are sent in plain text and could in theory be read by anyone who intercepts the connection. With an https connection, the data is securely encrypted, meaning that even if someone intercepted it, they wouldn't be able to read it.
    Starting in January 2017, Google's Chrome browser will begin to mark non-https pages as 'Insecure'. This warning may put off visitors to your site. Other browsers are expected to follow suit in due course.
    More details on this can be found HERE
    Additionally, Google is now using https as a ranking signal, meaning not having https could harm your site's ranking in Google. More details on this HERE.

    HOW IS THE MOBILE APP AFFECTED?
    Starting in January 2017, Apple is enforcing APP TRANSPORT SECURITY (ATS) for all new apps signed after that date. More details on this HERE. This means that apps signed after January 2017 must use secure https when making API calls and connecting to web services.
    We have updated vBulletin Mobile Suite to version 1.13 to publish apps using HTTPS, to meet Apple's App Transport Security requirement. After Jan. 1, you will not be able to submit updated apps to the iTunes App Store using earlier versions of Mobile Suite. Your current apps are fine and will continue to work with your site; you just won't be able to update them until you use v1.13.

    HOW DO I CONVERT MY FORUM TO HTTPS?
    The first thing you will need is an https certificate. In most cases, the first port of call for this will be your web host. https certificates are commonly referred to as SSL certificates, although these days they are usually actually TLS certificates. These are protocols used for https. TLS stands for Transport Socket Layer, and is the successor to SSL, which stands for Secure Socket Layer. You don't really need to concern yourself with these two protocols, but if you are interested, technical details can be found HERE.
    In most cases, your host will make a small charge for an https certificate. This is generally an annual fee which needs to be renewed. Failure to renew it will cause users to receive a warning in their browser that the certificate has expired, so it's vital to keep this up to date. https certificates are generally tied to a specific domain. The certificate will need to be installed on your server - again, generally your host will do this for you.

    You are not tied to buying the certificate from your host, however it is generally the easiest option if you're not well versed in doing this type of thing. If you purcahse one from a third party, you will normally find instructions on your web hosts website for how to perform the installation of the certificate yourself. For example, one hosting company has a guide HERE. There is another guide HERE. Use these guides at your own risk - vBulletin does not endorse and has not tested any of the guides linked to here. If you are unsure - speak to your host, who should be happy to help.

    I HAVE MY CERTIFICATE INSTALLED - WHAT NEXT?
    The next step is quite simple. Log into your vBulletin AdminCP, and then follow the appropriate instructions below for your version.

    vBulletin 3
    Go to vBulletin Options > vBulletin Options > Site Name / URL / Contact Details.
    Edit 'Forum URL' and add the 's' into the URL.
    For example, if your URL is http://www.contoso.com/forum, change it to https://www.contoso.com/forum

    Then go to Settings > vBulletin Options > vBulletin Options > Server Settings & Optimization Options > Use Remote YUI
    Set this to Google.

    vBulletin 4
    Go to Settings > Options > Site Name / URL / Contact Details.
    Edit 'Forum URL' and add the 's' into the URL.
    For example, if your URL is http://www.contoso.com/forum, change it to https://www.contoso.com/forum

    Then go to Settings > Options > Server Settings & Optimization Options > Use Remote YUI
    Set this to Google.

    vBulletin 5
    Go to vBulletin Options > vBulletin Options > Site Name / URL / Contact Details.
    Edit these three settings: 'vBulletin URL'; 'Login URL'; 'Core URL' and add the 's' into the URL.
    For example, if your URL is http://www.contoso.com/forum, change it to https://www.contoso.com/forum
    NOTE: Do not remove the word 'core' at the end of the core URL. You will break your site!

    Then go to Settings > Options > Server Settings & Optimization Options > Use Remote jQuery
    Set this to Google.

    The key to all three vBulletin versions is that all you do in the URL settings is change http to https. Do not alter any other part of the URL.

    Once you have changed these settings, go to AdminCP > Maintenance > General Update Tools, and rebuild the styles. (In vB3 this is AdminCP > Maintenance > Update Counters). Leave the default settings and just run this update tool.

    ANYTHING ELSE?
    Your site should now load and run normally when using https in the URL. However, you now need to redirect any http traffic to https, so that everyone using your site uses the secure connection.
    Again, in most cases, the simplest way to arrange this is to ask your host to configure it for you. They shouldn't charge for doing this, and it won't take them very long.
    If you'd rather do it yourself, it involves playing about with special files used by different types of server software - For instance, a server running 'Apache' will use an '.htaccess' file, whereas a server running IIS will use a 'web.config' file. If you don't know which server software your server is running, speak to your host. GoDaddy have a useful guide to making these changes HERE. However, these files can be quite tricky to work with, and an incorrect entry will break your site. It's much simpler to get your host to do it!

    THAT'S IT!
    You shouldn't encounter any difficulties and your site should be showing a green padlock in most browsers.
    You may run into issues with 'embedded images', where people have embedded external images or videos from third party sites into your posts, where those sites are or were not using https. These will trigger what is called a 'Mixed Content Warning' in the padlock area of the browser. In practice, what this means is that such embedded images or videos will not show and users may just see a blank space. You should aim to convert these images to attachments, subject to copyright, though this will be a manual task and can be fairly arduous if there are lots of them. Alternatively you can manually edit the embedded URL to change it to https. This will work for major sites like YouTube, but on some sites it may not work if https is not available. There are some third party add-ons that can help with this problem such as THIS ONE, however vBulletin cannot provide official support for third party code.

    If you have any questions regarding this guide, please post in the correct support forum for your version.
    Last edited by Mark.B; Thu 4th May '17, 12:24pm.

    • Peter Walker
      #3
      Peter Walker commented
      Editing a comment
      There is an important aspect that you need to check as well, particularly if you are running vBulletin 3 (possibly 4 as well, I have not checked - vBulletin 5 no longer offers Yahoo as an option).

      This description applies to vBulletin 3:
      Go to vBulletin Options -> vBulletin Options -> Server Settings and Optimization Options
      Right at the bottom, there is the option "Use Remote YUI" that can be set to "None", "Yahoo!" or "Google."

      Make sure this is set to either "None" (Javascript files are served by your own server) or "Google" (hosted by Google). The "Yahoo" service DOES NOT SUPPORT SSL so if this to set to Yahoo, your forum will not work correctly with SSL (https). Symptoms for this are that the enhanced editor will not work (buttons are frozen) and non-Chrome browsers will be unable to post due to an error saying their post does not have 10 characters (when it does). Additionally, drop-down menus like "Community" will not work, etc. As you can see, it is very important to have this set correctly when using SSL.

      Another tip for those considering switching to SSL, yet were put off by the high costs and complexity of installing it. Check out "Let's Encrypt" which offer a free SSL service. It is really free for ever, not a free trial, etc. If you have your own webserver, it is easy to install. If you are lucky enough to have Plesk, there is a special Plesk extension which makes it really easy to secure your websites. I have no affiliation with that service, I just wanted to let people know that you can now have SSL for free. The installed certificates are recognised by all major browsers.
      https://letsencrypt.org/

    • Wayne Luke
      #4
      Wayne Luke commented
      Editing a comment
      vBulletin 5 does not use YUI in its interface.

    • Glenn Vergara
      #5
      Glenn Vergara commented
      Editing a comment
      If you have posts that that have embedded external images that are not using https, you will get a mixed content error in the browser console and the padlock icon in the address bar will not be green. To prevent that from happening, you can block all the mixed content using this meta tag:

      Code:
      <meta http-equiv="Content-Security-Policy" content="block-all-mixed-content"/>
      That meta tag should be placed inside the <head> tag. For vB5, you can paste it in the head_include template. For vBCloud, you can utilize the Search Engine Verification option in AdminCP > Settings > Options to insert the meta tag.

      See these links for reference:
      https://developers.google.com/web/fu...-mixed-content
      https://developer.mozilla.org/en-US/...-mixed-content
    Posting comments is disabled.

About the Author

Collapse

Mark.B Find out more about Mark.B

Article Tags

Collapse

advanced (5) album (1) android (2) api (29) array (17) beginner (17) blog (4) blogs (1) calendar (2) cms (2) forum (3) forumbits (1) forums (4) Intermediate (5) iphone (3) mapi (30) methods (10) mobile (34) pagenav (1) post (1) style (2) threads (4) tutorial (1) vb5howto (5) vBulletin (5)

Latest Articles

Collapse

  • Enabling Two-Factor Authentication
    Wayne Luke
    vBulletin 5.3.0 and higher will allow site owners to enable Two-Factor Authentication for Administrator and Moderator functionality. This is an extra layer of security provided to make sure your user data remains as safe as possible. Two-Factor Authentication works in conjunction with an app on the user's smartphone, tablet, or computer. These apps provide a security token that lasts a limited time before expiring. The security token is created using industry standard algorithms and a unique string...
    Tue 4th Apr '17, 8:38am
  • How to moderate the posts of new users only
    Wayne Luke
    To help combat spam, many users opt to have new user’s posts moderated until they’ve made a specific number of posts. This allows the Admin/Moderator team to keep potentially malicious posts out of the public eye until a user has effectively passed a ‘probationary period’ as a member of the site.

    In order to do this, you will need to create a custom usergroup and a promotion.

    Creating a Custom Usergroup
    First, you need to setup the usergroup for your non-Moderated...
    Wed 22nd Feb '17, 9:13am
  • Rebuilding the Sphinx index
    Wayne Luke
    From time to time, we will need to update the indexing schema for the Sphinx server. In order for this fix to take effect, you will need to update the sphinx schema for the index. Follow these steps to rebuild your Sphinx Search Schema.
    1. Stop the Sphinx service on your server.
    2. Replace your existing Sphinx configuration file (vbulletin-sphinx.php) with the one provided in the current version of vBulletin 5 Connect. You can find this file in the do_not_upload directory.
    3. Update the file as provided
    ...
    Fri 3rd Feb '17, 1:01pm
  • Converting your forum to https
    Mark.B
    CONVERTING YOUR FORUM TO HTTPS
    Applies to self-hosted versions of:
    vBulletin 3; vBulletin 4; vBulletin 5;
    Cloud sites have https enabled by default and you do not need to do anything.

    This FAQ explains how to convert your vBulletin forum to use secure https (SSL) rather than http, and why you might need to.
    Note: This guide contains links to external sites. vBulletin Solutions is not responsible for the content of external links and cannot be held responsible...
    Fri 9th Dec '16, 2:59am
  • Creating a Custom Style with vBulletin 5 Connect.
    Wayne Luke
    This tutorial will walk you through the steps of creating your custom style for a vBulletin 5 Connect site using Style Variables. The tutorial assumes that you have already uploaded your custom logo using the Quick Setup Tool in Site Builder....
    Tue 5th May '15, 7:47am
  • Using the Search JSON
    Dominic
    Using the advanced editor you can create powerful search modules. Following you find possible filters / parameters for using within these modules:
    The search JSON parameter has the following format:

    :
    { "filter": <value>, "filter": <value>, ... }
    <value> may be any valid string, number or JSON structure and will be interpreted by the specified filter. Filters not listed below are ignored.

    Filters

    The valid filters...
    Wed 28th Jan '15, 12:51pm
Working...
X