http://joomlawebhosting.ca/joomla-15-tips/63-joomla-ssl-https-setup.html
Joomla can flip in and out of SSL mode.
Once it receives a command to go into SSL it will stay that way until getting a command to go back to http.
- The site can be set to be SSL all the time using “Force SSL” in Global Configuration.
- Switching to and from SSL mode is triggered by a menu item setting.
- The front end user Login module can be set to post to https instead of http.
There’s a Joomla Plugin called SSL Redirect plugin by Yireo software that might simplify the setup if some parts of the site are SSL and some not.
Joomla Admin security checklist:
http://docs.joomla.org/Category:Security_Checklist
Site Protection Extensions:
http://extensions.joomla.org/extensions/access-a-security/site-security/site-protection
