SSL not enforced

More
10 months 1 week ago #205713 by krojQu
SSL not enforced was created by krojQu
I have this error:

Warning: Please enforce SSL encrpytion in Global settings/Security after SSL is properly configured for your webserver.

How should I configured this?

Please Log in to join the conversation.

More
10 months 1 week ago #205715 by Joffm
Replied by Joffm on topic SSL not enforced
Hi,
as it says, it is not an error, it's a warning.
It remings you to change your environment to a secure connection.

You do this here:
"Configuration / Global Settings / Security"

But only after your webserver is configured to support "https"

Otherwise you will not be able to access LimeSurvey.

Joffm


Volunteers are not paid.
Not because they are worthless, but because they are priceless
Attachments:

Please Log in to join the conversation.

More
10 months 1 week ago #205717 by krojQu
Replied by krojQu on topic SSL not enforced
I didn't check if my webserver supports https and I clicked "On" too fast and I don't have access. Is there any solution now? Need to configure a webserver?

Please Log in to join the conversation.

More
10 months 1 week ago #205719 by Joffm
Replied by Joffm on topic SSL not enforced
Two solutions
forums.limesurvey.org/forum/installation...on-by-mistake#202627

Any of these two posts.


Joffm


Volunteers are not paid.
Not because they are worthless, but because they are priceless
Attachments:
The following user(s) said Thank You: krojQu

Please Log in to join the conversation.

More
10 months 1 week ago #205722 by krojQu
Replied by krojQu on topic SSL not enforced
Really thank you Joffm for help, it works now.

But btw maybe you know where I find logs? When I tried configure Lime with Active Directory and next login with LDAP authentication I only see an alert "Invalid username and / or password!". But I want to know what I fill incorrectly in AuthLDAP.

Please Log in to join the conversation.

More
10 months 1 week ago #205723 by Joffm
Replied by Joffm on topic SSL not enforced
You asked this in your other post.
Do not cross post, please.

Joffm


Volunteers are not paid.
Not because they are worthless, but because they are priceless

Please Log in to join the conversation.

More
1 month 2 weeks ago - 1 month 2 weeks ago #217263 by kordan
Replied by kordan on topic SSL not enforced
My LimeSurvey server (debian 10) is behind a reverse proxy.
I have a couple of certificates covering the server. One in the revProxy and one in LimeSurvey server.
In spite of this in limeSurvey web application I get the Warning: Please enforce SSL encrpytion in Global settings/Security after SSL is properly configured for your webserver.

What am I missing?

The vHost on limeSurvey server has:

<IfModule mod_ssl.c>
<VirtualHost _default_:443>

ServerAdmin This email address is being protected from spambots. You need JavaScript enabled to view it.

DocumentRoot /path/to/somewhere

ErrorLog ${APACHE_LOG_DIR}/lsurvey_error.log
CustomLog ${APACHE_LOG_DIR}/lsurvey_access.log combined

SSLEngine on

SSLCertificateFile /etc/ssl/certs/lsurvey.pem
SSLCertificateKeyFile /etc/ssl/private/lsurvey.key

and mol ssl is enabled

Thanks in advance
Last edit: 1 month 2 weeks ago by DenisChenu. Reason: Usage of example.com

Please Log in to join the conversation.

More
1 month 2 weeks ago #217265 by DenisChenu
Replied by DenisChenu on topic SSL not enforced
What id the real relation with LimeSurvey ?

SSL on webserver are not related to LimeSurvey

And : why you post on an unrelated topic ?

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development . I don't answer to private message.

Please Log in to join the conversation.

More
1 month 2 weeks ago - 1 month 2 weeks ago #217269 by kordan
Replied by kordan on topic SSL not enforced
SSL on webserver is not related to LimeSurvey
but LimeSurvey dispaying an error that I don't know how to justify is a limesurvey topic, IMHO.
I am sorry if I was off topic. I didn't feel. Where am I supposed to ask for this LimeSurvey issue? To Apache2 SSL forums?
Last edit: 1 month 2 weeks ago by kordan.

Please Log in to join the conversation.

More
1 month 2 weeks ago #217270 by DenisChenu
Replied by DenisChenu on topic SSL not enforced
Oh

It's worst than i think the 1st time …
You post on a topic without read the answer !

Hi,
as it says, it is not an error, it's a warning.
It remings you to change your environment to a secure connection.

You do this here:
"Configuration / Global Settings / Security"

But only after your webserver is configured to support "https"

Otherwise you will not be able to access LimeSurvey.

Joffm


Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development . I don't answer to private message.

Please Log in to join the conversation.

More
1 month 2 weeks ago #217273 by kordan
Replied by kordan on topic SSL not enforced
I am sorry I am not able to let you understand.
I read, trust me.
and I even usually call my server using https.
And I also make use of the test link.

My question was asking for a reply like: "LimeSurvey check for this in the code. Maybe you forget this deatil."
I am sorry you can't understand.

Please Log in to join the conversation.

More
1 month 2 weeks ago #217274 by DenisChenu
Replied by DenisChenu on topic SSL not enforced
It remings you to change your environment to a secure connection.

Then: set to yes …

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development . I don't answer to private message.

Please Log in to join the conversation.

More
1 month 2 weeks ago #217275 by kordan
Replied by kordan on topic SSL not enforced
Setting it to yes, LS closes me out. I tried.

Please Log in to join the conversation.

More
1 month 2 weeks ago #217301 by holch
Replied by holch on topic SSL not enforced

Setting it to yes, LS closes me out. I tried.


Then you do not have a SSL certificate setup correctly.

You do not NEED to set "force SSL". It is a warning and recommendation from Limesurvey. if you can't set "Force SSL" to yes, then leave it and ignore the warning. It will not go away. Believe me.

I answer at the LimeSurvey forum in my spare time, I'm not a LimeSurvey GmbH employee.
No support via private message.

Please Log in to join the conversation.

More
1 month 2 weeks ago #217303 by DenisChenu
Replied by DenisChenu on topic SSL not enforced

Setting it to yes, LS closes me out. I tried.

 

And WHY you don't explain this on the 1st post ?????
(again: why post on another topic).

With some proxies : SSL is need to be disabled between server and proxies. Proxies must  be reviewed (because SSL must be activated between proxy and server), but clearly : it's not related to LimeSurvey ...

The answer for LimeSurvey part are here

Two solutions
forums.limesurvey.org/forum/installation...on-by-mistake#202627

Any of these two posts.


Joffm


Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development . I don't answer to private message.

Please Log in to join the conversation.

Start now!

Just create your account and start using Limesurvey today.

Register now