Jump to content
IGNORED

TST is Converting to HTTPS


iacas
Note: This thread is 2927 days old. We appreciate that you found this thread instead of starting a new one, but if you plan to post here please make sure it's still relevant. If not, please start a new topic. Thank you!

Recommended Posts

  • Administrator

Starting next Tuesday, March 22, we'll be taking a multi-step and thus multi-day (possibly multi-week) move toward switching The Sand Trap from being transmitted over HTTP to being transmitted over HTTPS.

At this point, there's nothing to worry about with just being HTTP - any of the transactions you conduct (like to buy a Supporter membership from our store) are handled over HTTPS - and the only data transmitted over HTTP is your login information. This will be some of the first areas we adjust.

Please use this thread to report anything like broken images or anything else that seems out of place. Any errors about an insecure page, an out-of-date certificate, etc. belong here too.

Thank you.

Erik J. Barzeski —  I knock a ball. It goes in a gopher hole. 🏌🏼‍♂️
Director of Instruction Golf Evolution • Owner, The Sand Trap .com • AuthorLowest Score Wins
Golf Digest "Best Young Teachers in America" 2016-17 & "Best in State" 2017-20 • WNY Section PGA Teacher of the Year 2019 :edel: :true_linkswear:

Check Out: New Topics | TST Blog | Golf Terms | Instructional Content | Analyzr | LSW | Instructional Droplets

Link to comment
Share on other sites

Awards, Achievements, and Accolades

  • 2 weeks later...
  • Administrator

The first few steps are done. Logins are now done securely.

Erik J. Barzeski —  I knock a ball. It goes in a gopher hole. 🏌🏼‍♂️
Director of Instruction Golf Evolution • Owner, The Sand Trap .com • AuthorLowest Score Wins
Golf Digest "Best Young Teachers in America" 2016-17 & "Best in State" 2017-20 • WNY Section PGA Teacher of the Year 2019 :edel: :true_linkswear:

Check Out: New Topics | TST Blog | Golf Terms | Instructional Content | Analyzr | LSW | Instructional Droplets

Link to comment
Share on other sites

Awards, Achievements, and Accolades

  • Administrator

We're doing a little thing right now where all http:// requests are redirected/rewritten at the header level with HTTPS.

If that works well, we'll enable the base_url config file thing to https://.

Erik J. Barzeski —  I knock a ball. It goes in a gopher hole. 🏌🏼‍♂️
Director of Instruction Golf Evolution • Owner, The Sand Trap .com • AuthorLowest Score Wins
Golf Digest "Best Young Teachers in America" 2016-17 & "Best in State" 2017-20 • WNY Section PGA Teacher of the Year 2019 :edel: :true_linkswear:

Check Out: New Topics | TST Blog | Golf Terms | Instructional Content | Analyzr | LSW | Instructional Droplets

Link to comment
Share on other sites

Awards, Achievements, and Accolades

I am getting "unsafe" warning that TST's certificate can't be verified. That hackers could get into my account. This is showing up on my phone, and laptop. Anyone else seeing this?

In My Bag:
A whole bunch of Tour Edge golf stuff...... :beer:

Link to comment
Share on other sites

Awards, Achievements, and Accolades

6 hours ago, Patch said:

I am getting "unsafe" warning that TST's certificate can't be verified. That hackers could get into my account. This is showing up on my phone, and laptop. Anyone else seeing this?

I have not received that warning. 

-Jerry

Driver: Titleist 913 D3 (9.5 degree) – Aldila RIP 60-2.9-Stiff; Callaway Mini-Driver Kura Kage 60g shaft - 12 degree Hybrids: Callway X2 Hot Pro - 16 degree & 23 degree – Pro-Shaft; Callway X2 Hot – 5H & 6H Irons: Titleist 714 AP2 7 thru AW with S300 Dynamic Gold Wedges: Titleist Vokey GW (54 degree), Callaway MackDaddy PM Grind SW (58 degree) Putter: Ping Cadence TR Ketsch Heavy Balls: Titleist Pro V1x & Snell MyTourBall

"Golf is the closest game to the game we call life. You get bad breaks from good shots; you get good breaks from bad shots but you have to play the ball where it lies."- Bobby Jones

Link to comment
Share on other sites

Awards, Achievements, and Accolades

I believe this should have been posted over here,

TST to HTTPS

 

 

Matt Dougherty, P.E.
 fasdfa dfdsaf 

What's in My Bag
Driver; :pxg: 0311 Gen 5,  3-Wood: 
:titleist: 917h3 ,  Hybrid:  :titleist: 915 2-Hybrid,  Irons: Sub 70 TAIII Fordged
Wedges: :edel: (52, 56, 60),  Putter: :edel:,  Ball: :snell: MTB,  Shoe: :true_linkswear:,  Rangfinder: :leupold:
Bag: :ping:

Link to comment
Share on other sites

Awards, Achievements, and Accolades

I get a warning box from internet explorer asking of if I want to show all content. content.JPG

I click the "Show all Content" and the page reloads but nothing seems to be added or blocked. It's a tad strange. Besides that I haven't received any issues with the site otherwise yet.

 

Matt Dougherty, P.E.
 fasdfa dfdsaf 

What's in My Bag
Driver; :pxg: 0311 Gen 5,  3-Wood: 
:titleist: 917h3 ,  Hybrid:  :titleist: 915 2-Hybrid,  Irons: Sub 70 TAIII Fordged
Wedges: :edel: (52, 56, 60),  Putter: :edel:,  Ball: :snell: MTB,  Shoe: :true_linkswear:,  Rangfinder: :leupold:
Bag: :ping:

Link to comment
Share on other sites

Awards, Achievements, and Accolades

  • Administrator
7 hours ago, Patch said:

I am getting "unsafe" warning that TST's certificate can't be verified. That hackers could get into my account. This is showing up on my phone, and laptop. Anyone else seeing this?

What version?

13 minutes ago, saevel25 said:

I get a warning box from internet explorer asking of if I want to show all content. content.JPG

I click the "Show all Content" and the page reloads but nothing seems to be added or blocked. It's a tad strange. Besides that I haven't received any issues with the site otherwise yet.

What version?

BTW as a general rule, if one thing (say, a JavaScript file or an image)  isn't served over HTTPS, the page may throw a warning depending on your browser, version, and settings.

All said, the site is now more secure than it was yesterday. 99.9% of things are served HTTPS now.

Erik J. Barzeski —  I knock a ball. It goes in a gopher hole. 🏌🏼‍♂️
Director of Instruction Golf Evolution • Owner, The Sand Trap .com • AuthorLowest Score Wins
Golf Digest "Best Young Teachers in America" 2016-17 & "Best in State" 2017-20 • WNY Section PGA Teacher of the Year 2019 :edel: :true_linkswear:

Check Out: New Topics | TST Blog | Golf Terms | Instructional Content | Analyzr | LSW | Instructional Droplets

Link to comment
Share on other sites

Awards, Achievements, and Accolades

Huh?

:-\

Yours in earnest, Jason.
Call me Ernest, or EJ or Ernie.

PSA - "If you find yourself in a hole, STOP DIGGING!"

My Whackin' Sticks: :cleveland: 330cc 2003 Launcher 10.5*  :tmade: RBZ HL 3w  :nickent: 3DX DC 3H, 3DX RC 4H  :callaway: X-22 5-AW  :nike:SV tour 56* SW :mizuno: MP-T11 60* LW :bridgestone: customized TD-03 putter :tmade:Penta TP3   :aimpoint:

Link to comment
Share on other sites

Awards, Achievements, and Accolades

17 minutes ago, iacas said:

What version?

 IE 10.0.9

I never had any warnings show up on Chrome at my home computer.

Matt Dougherty, P.E.
 fasdfa dfdsaf 

What's in My Bag
Driver; :pxg: 0311 Gen 5,  3-Wood: 
:titleist: 917h3 ,  Hybrid:  :titleist: 915 2-Hybrid,  Irons: Sub 70 TAIII Fordged
Wedges: :edel: (52, 56, 60),  Putter: :edel:,  Ball: :snell: MTB,  Shoe: :true_linkswear:,  Rangfinder: :leupold:
Bag: :ping:

Link to comment
Share on other sites

Awards, Achievements, and Accolades

  • Administrator
Just now, saevel25 said:

 IE 10.0.9

I never had any warnings show up on Chrome at my home computer.

We just changed some things last night. At… 9pm or so?

Thanks.

Again, TST is totally "safe." You're not posting private financial information or anything like that anyway. We may need to update to a different (more widely recognized?) certificate, but more than likely it's that we have to simply find every last resource that's still coming to you via HTTP instead of HTTPS.

It's not as simple as looking at the code, either, because we employ a server trick to send files via HTTPS even when the code asks for HTTP, like our favicons (we're still looking to change those links out, too, though).

Erik J. Barzeski —  I knock a ball. It goes in a gopher hole. 🏌🏼‍♂️
Director of Instruction Golf Evolution • Owner, The Sand Trap .com • AuthorLowest Score Wins
Golf Digest "Best Young Teachers in America" 2016-17 & "Best in State" 2017-20 • WNY Section PGA Teacher of the Year 2019 :edel: :true_linkswear:

Check Out: New Topics | TST Blog | Golf Terms | Instructional Content | Analyzr | LSW | Instructional Droplets

Link to comment
Share on other sites

Awards, Achievements, and Accolades

Everything seems normal, I've log in using Edge and Chrome.

Chrome shows the Lock at https: and had a popup indicating a request to show notifications with the option to allow or block.

Edge also show the Lock which indicates the website identification - using Comoro Secure identifying the site. The connection to the server is encrypted.

8 hours ago, Patch said:

I am getting "unsafe" warning that TST's certificate can't be verified

I think "certificates" may need to be renewed as the site is now basically using the HTTPS address.

Try signing out and log on, a new certificate should then be issued.

Johnny Rocket - Let's Rock and Roll and play some golf !!!

Link to comment
Share on other sites

Awards, Achievements, and Accolades

Some images are not hosted via HTTPS:

1l22eL5.png

 

Causing them to not load.

Edited by pumaAttack

Tony  


:titleist:    |   :tmade:   |     :cleveland: 

Link to comment
Share on other sites


  • Administrator
5 hours ago, Club Rat said:

Everything seems normal, I've log in using Edge and Chrome.

For people with up-to-date browsers, that is about how it works. Really smoothly and well.

5 hours ago, Club Rat said:

I think "certificates" may need to be renewed as the site is now basically using the HTTPS address.

No, the certificates are a few days old and are good for three years. Our issuing agency may not be in every list, so we may need to re-buy new ones, which we'll do if we must, but that's unlikely and these should work just fine. They're just being used mostly to encrypt traffic.

5 hours ago, Club Rat said:

Try signing out and log on, a new certificate should then be issued.

Not quite how it works, but signing out, emptying your cache and cookies, and signing back in are never a bad idea.

12 minutes ago, pumaAttack said:

Some images are not hosted via HTTPS:

1l22eL5.png

Causing them to not load.

I don't know what images you're using, but when I type : nike : or : titleist : (without the spaces) they work just fine: :nike::titleist:

Screen Shot 2016-03-31 at 2.13.51 PM.png

There's "titleist.png" being loaded over HTTPS.

On this page, right now, there are only a few things loaded via HTTP: c2_beer.gif and "taylormade.png". Both are probably in a signature.

(Note: :beer: in @Patch's signature has been fixed, and "taylormade.png" sorted itself out:

Screen%20Shot%202016-03-31%20at%202.18.0

(And that image, which is not uploaded but which is embedded, will cache on the local server and be served via HTTPS too!)

Erik J. Barzeski —  I knock a ball. It goes in a gopher hole. 🏌🏼‍♂️
Director of Instruction Golf Evolution • Owner, The Sand Trap .com • AuthorLowest Score Wins
Golf Digest "Best Young Teachers in America" 2016-17 & "Best in State" 2017-20 • WNY Section PGA Teacher of the Year 2019 :edel: :true_linkswear:

Check Out: New Topics | TST Blog | Golf Terms | Instructional Content | Analyzr | LSW | Instructional Droplets

Link to comment
Share on other sites

Awards, Achievements, and Accolades

26 minutes ago, iacas said:

 

I don't know what images you're using, but when I type : nike : or : titleist : (without the spaces) they work just fine: :nike::titleist:

Screen Shot 2016-03-31 at 2.13.51 PM.png

There's "titleist.png" being loaded over HTTPS.

On this page, right now, there are only a few things loaded via HTTP: c2_beer.gif and "taylormade.png". Both are probably in a signature.

 

I'm using the same signature icons I have used for years.  I will go update those in my profile. Thanks!

Tony  


:titleist:    |   :tmade:   |     :cleveland: 

Link to comment
Share on other sites


  • Administrator
Just now, pumaAttack said:

I'm using the same signature icons I have used for years.  I will go update those in my profile. Thanks!

I already did. You were using them with an IP address in the URL.

Erik J. Barzeski —  I knock a ball. It goes in a gopher hole. 🏌🏼‍♂️
Director of Instruction Golf Evolution • Owner, The Sand Trap .com • AuthorLowest Score Wins
Golf Digest "Best Young Teachers in America" 2016-17 & "Best in State" 2017-20 • WNY Section PGA Teacher of the Year 2019 :edel: :true_linkswear:

Check Out: New Topics | TST Blog | Golf Terms | Instructional Content | Analyzr | LSW | Instructional Droplets

Link to comment
Share on other sites

Awards, Achievements, and Accolades

1 minute ago, iacas said:

I already did. You were using them with an IP address in the URL.

Thanks!  

I think I got them from the old emoji list.  

Tony  


:titleist:    |   :tmade:   |     :cleveland: 

Link to comment
Share on other sites


It's throwing up a "This page is unsafe" on Android Lollipop... It's saying that it's my OS blocking it.

What's in Shane's Bag?     

Ball: 2022 :callaway: Chrome Soft Triple Track Driver: :callaway:Paradym Triple Diamond 8° MCA Kai’li 70s FW: :callaway:Paradym Triple Diamond  H: :callaway: Apex Pro 21 20°I (3-PW) :callaway: Apex 21 UST Recoil 95 (3), Recoil 110 (4-PW). Wedges: :callaway: Jaws Raw 50°, 54°, 60° UST Recoil 110 Putter: :odyssey: Tri-Hot 5K Triple Wide 35”

Link to comment
Share on other sites

Awards, Achievements, and Accolades

Note: This thread is 2927 days old. We appreciate that you found this thread instead of starting a new one, but if you plan to post here please make sure it's still relevant. If not, please start a new topic. Thank you!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×
×
  • Create New...

Important Information

Welcome to TST! Signing up is free, and you'll see fewer ads and can talk with fellow golf enthusiasts! By using TST, you agree to our Terms of Use, our Privacy Policy, and our Guidelines.

The popup will be closed in 10 seconds...