Sichern Sie Ihre Website mit HTTPS

Um Kreditkarten auf Ihrer Website zu akzeptieren und möglichst wenig PCI-konform müssen Sie über ein SSL-Zertifikat verfügen und HTTPS auf allen Seiten verwenden, die Kreditkartendaten erfassen. HTTPS bietet eine Authentifizierung für Ihre Website und den zugehörigen Webserver, die vor Man-in-the-Middle-Angriffen schützt.

Additionally, it provides bidirectional encryption of communications between a customer’s browser and your server, which protects against eavesdropping and tampering with and/or forging the contents of the communication.

In this article we’ll cover the steps you’ll need to go through in order to ensure your site is secure. This article may also be helpful: http://www.wpbeginner.com/wp-tutorials/how-to-add-ssl-and-https-in-wordpress/.

Kaufen und installieren Sie ein SSL-Zertifikat

Es gibt eine Reihe von Unternehmen, bei denen Sie SSL-Zertifikate erwerben können, darunter GoDaddyVeriSign und GeoTrust to name few. Once you’ve purchased an SSL certificate, you’ll need to work with your hosting provider to get it set up on your server.

Prüfen Sie, ob Ihr SSL-Zertifikat korrekt installiert ist

Once you’ve worked with your hosting provider to get the SSL certificate installed, you can verify that everything is set up correctly by using this SSL-Prüfer.

WordPress SSL-Einstellungen prüfen

If you’re going to utilize the HTTPS plugin we recommend below then you’ll want to make sure that WordPress isn’t forcing SSL. Do this by going to the wp-config.php file and checking if ‘FORCE_SSL_ADMIN’ is being defined there and if so, make sure it’s set to ‘false’. Here are Detaillierte Anweisungen für die Arbeit mit der Force-SSL-Einstellung.

Sichere Seiten auf Ihrer Website

Once your SSL certificate has been successfully installed, you’ll want to ensure that HTTPS is used on all the pages on your site that collect sensitive information. This can easily be done with the WordPress HTTPS Plugin.

HINWEIS: If you follow this link you’ll see that the plugin has not been updated in over two years. This is ok. The plugin is doing something very specific and has a narrow focus so updates aren’t required as often as they would be for more complex plugins. Additionally, WordPress HTTPS is a recommendation, not a requirement. There are other WordPress HTTPS plugins available (https://wordpress.org/plugins/search.php?q=https). Sie können jedes Plugin verwenden, das die Verwendung von HTTPS auf Ihrer Website erzwingen kann.

WICHTIG! Nachdem Sie das WordPress HTTPS-Plugin aktiviert haben, gehen Sie zu den Einstellungen und im Bereich Allgemeine Einstellungen Abschnitt stellen Sie sicher, dass die Ausschließlich SSL erzwingen ist nicht aktiviert. Wenn diese Option aktiviert ist, ändert das WordPress-HTTPS-Plugin versehentlich die URL auf den MemberMouse-Kassenformularen so, dass sie unsicher ist. Dies führt dazu, dass Kunden in einigen Browsern eine Warnmeldung angezeigt wird, wenn sie versuchen, das Kassenformular abzuschicken. Um dies zu vermeiden, stellen Sie einfach sicher, dass die Ausschließlich SSL erzwingen nicht markiert ist, wie unten dargestellt:



Sie sollten auch URL-Filter für das php-Prozess-Skript hinzufügen, das MemberMouse für Transaktionen verwendet. Diese können ebenfalls im Abschnitt URL-Filter hinzugefügt werden. Sie müssen die folgenden URLs hinzufügen:

/wp-content/plugins/membermouse/api/processOrder.php

/wp-content/plugins/membermouse/scheduler/handler.php

Und wenn Sie Social Login verwenden: /wp-content/plugins/membermouse/endpoints/auth.php



Gehen Sie dann zu jeder Seite, die gesichert werden muss, und kreuzen Sie an Sicherer Posten im HTTPS module. You’ll want to do this for the MemberMouse Checkout and My Account core pages and any page you’ve included a MemberMouse checkout form on.

Stellen Sie sicher, dass Ihre Seiten vollständig gesichert sind

Once you’ve installed a plugin to handle HTTPS and you’ve configured which pages should use HTTPS, you’ll want to check and make sure there aren’t any insecure items being loaded on your secure pages as this will typically cause the browser to show a warning to the user informing them that the page is not secure.

In some browsers, like Chrome, they’re more strict and will terminate rendering the page when an insecure item is encountered. You can Verwenden Sie dieses Tool, um sicherzustellen, dass Ihre Seiten vollständig sicher sind.. Wenn der Bericht Ihnen mitteilt, dass Sie unsichere Elemente auf Ihrer Seite haben, verwenden Sie diese Ressource, um die unsicheren Elemente zu reparieren.

War dieser Artikel hilfreich?

Verwandte Artikel