moodle 2.0 calling secure protocol wrongly (https)

moodle 2.0 calling secure protocol wrongly (https)

juss pitti發表於
Number of replies: 13

I have installed moodle 2.0 from scratch with Installatron and without it, and the initial page user/editadvanced.php is triying to send the info to https for some uknown reason, I am not using that protocol, and I am using moodle out of the box.

1.9.10 worked perfectly, so I am just going to say it: sorry but moodle 2.0 is not stable not "BEST CHOICE FOR A NEW SERVER!"

評比平均分數: -
In reply to juss pitti

Re: moodle 2.0 calling secure protocol wrongly (https)

Mark Johnson發表於
Core developers的相片 Particularly helpful Moodlers的相片 Peer reviewers的相片 Plugin developers的相片

Hi Juss,

The HTTPS-related behaviour of this pages appears to be exactly the same as in 1.9. That is, if you have HTTPS Logins enabled (Site Administration -> Security -> HTTP Security) then it (and other sensitive pages such as the login form) are served via HTTPS. If you don't use HTTPS (which you probably should on these pages unless it's a local test server) then you can disable this setting.

In reply to Mark Johnson

Re: moodle 2.0 calling secure protocol wrongly (https)

juss pitti發表於

Hi Mark

Thanks for your reply and advice, I can see that the moodle community is a great help.

My instalation is brand new and HTTPS Logins is not enabled by default. Anyway I checked and is dissabled.

My only guess is that most of the people here are using https protocol as you say we should, so you guys have not detected this bug.

In reply to Mark Johnson

Re: moodle 2.0 calling secure protocol wrongly (https)

Jim Judges發表於

I have found that my EZPZ cPanel Softaculous installation of Moodle 2.0.1 produces an error when trying to add a new course, after editing course settings and clicking save changes an error "404 not found The resource requested could not be found on this server!" appears.

Now please note I am not really technically minded BUT I think the reason may be that I am running on Litespeed V5.5 BECAUSE the cPanel Sofataculous demo version of Moodle will add courses okay but this is running with Apache 2.0 instead of Litespeed.

I am submitting this information as it may help someone with more technical knowledge understand this problem better and also in the hope that someone may be able to advise me how to switch from Litespeed to Apache in cPanel to see if this works? Or if someone else has had this problem have they resolved it?

All the best and happy Moodling,

Jim 微笑


In reply to juss pitti

Re: moodle 2.0 calling secure protocol wrongly (https)

Marcus Green發表於
Core developers的相片 Particularly helpful Moodlers的相片 Plugin developers的相片 Testers的相片
I have been regularly installing the betas/release candidates for Moodle2 on Windows 7 and have yet to see any call to https. If I do change the protocol to https I get big obvious message that there is a security issue.
In reply to Marcus Green

Re: moodle 2.0 calling secure protocol wrongly (https)

juss pitti發表於

Hi Marcus,

Thanks for your reply, I have installed a local server with moodle 2.0 and works ok out of the box. So I guess the problem is on certain server configurations.

I am using a shared hosting with a regular cpanel and litespeed, not very different to apache in fact.

I will review all the software requirements, but it is strange because I passed all the test moodle does when installing.

Thanks anyway and let me know if you think about any workaround, It would be great to use the latest version if is not to buggy.

In reply to juss pitti

Re: moodle 2.0 calling secure protocol wrongly (https)

Mark Johnson發表於
Core developers的相片 Particularly helpful Moodlers的相片 Peer reviewers的相片 Plugin developers的相片

Hi Juss,

If you're able to consistently reproduce this, please consider filing the bug on the tracker with all relevant information (Screenshot of HTTP Security page, web server config files, Operating System details etc).  It may be something specific to your environment that the QA process didn't pick up on, as is bound to happen when a new system starts being used on real setups.  The best way to get it sorted is to report it there.

評比平均分數:Useful (2)
In reply to Mark Johnson

Re: moodle 2.0 calling secure protocol wrongly (https)

juss pitti發表於

Hello Mark, thanks for your comment and help, I will open the bug on the tracker with the screenshots, I just want to know what do you mean by "consistently reproduce this".  I have tried installing more than one time with the same result, but I have only one litestep server to test this, and of course my localserver (my laptop). How can I "consistently reproduce this" ?

Thanks

In reply to juss pitti

Re: moodle 2.0 calling secure protocol wrongly (https)

Mark Johnson發表於
Core developers的相片 Particularly helpful Moodlers的相片 Peer reviewers的相片 Plugin developers的相片

Hi Juss,

Sorry for the late reply! By "consistenty reproduce" I mean, can you provide a set of steps which someone else could follow to end up with the same problem as you (in this case, it would include how you configured your web server, how you configured Moodle during installation, and how you came to the error).

In reply to juss pitti

Re: moodle 2.0 calling secure protocol wrongly (https)

Paul Nicholls發表於

Hi Juss,

Did you manage to resolve this issue?  We're seeing the exact same behaviour on a cpanel/litespeed setup.  We also now have "loginhttps" explicitly set to false in the site's config.php, to no avail.

Regards,
Paul

In reply to juss pitti

Re: moodle 2.0 calling secure protocol wrongly (https)

Raven Dawson發表於

Thanks for clearing it up. I wasn't aware that we should use protocol https with moodle and my https wasn't also enabled by default.

In reply to Raven Dawson

Re: moodle 2.0 calling secure protocol wrongly (https)

John Bonner發表於

Again, I ask what type server is used for your hosted site? If it is Zeus, there's a posting on the Securicy and Privacy forum which may help.

JB