HTTPS encrypts the connection between a visitor's browser and your website using an SSL/TLS certificate. Having a certificate installed isn't enough on its own, though. Visitors who type http:// or follow an old link can still reach the unencrypted version. Forcing HTTPS redirects them to the secure version every time.
Why every site needs HTTPS
- Browser warnings: modern browsers label plain HTTP pages as "Not secure", especially pages with forms.
- Privacy: logins, contact forms and search terms are protected from anyone watching the network, for example on public Wi-Fi.
- Features: many browser features, such as location access, service workers and some payment and login integrations, only work over HTTPS.
- Search: search engines prefer secure pages, and HTTPS can affect your ranking.
Before you start
Make sure an SSL certificate is active on the domain first. The free SSL included with your plan is fine. See "How to Activate the Free SSL Certificate in StackCP". If you force HTTPS with no certificate installed, visitors will get a security error.
Method 1: The Force HTTPS switch in StackCP (recommended)
- Sign in to your FimuroHost client area at https://app.fimurohost.com.
- Go to Services and select the hosting plan for the site.
- Click Login to Control Panel / StackCP. StackCP opens for that site without a separate password.
- In StackCP, click SSL/TLS in the Security section. If you see a package list, go to Manage Hosting → Manage first.
- Click Enable Force HTTPS.
That's it. No code is needed, and you can turn it off again from the same place.
Method 2: A rule in .htaccess
If you prefer to manage redirects yourself, add these lines to the top of the .htaccess file in your site's root folder (usually public_html). You can edit it with the StackCP File Manager or an SFTP client:
RewriteEngine On RewriteCond %{ENV:HTTPS} !on RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]
- If your
.htaccessalready has aRewriteEngine Online, which WordPress adds, don't add a second one. Put the other two lines above the WordPress block. R=301makes it a permanent redirect, which is what search engines expect.- To always send visitors to one exact hostname, replace
%{HTTP_HOST}with it, e.g.https://www.example.com/$1.
Use only one method at a time. Running both the StackCP switch and your own rule can cause redirect loops.
Common problems
- "Not secure" after forcing HTTPS: check that the certificate is installed and active, then look for mixed content (images, CSS or scripts still loading over
http://). - "Too many redirects": a plugin (such as an SSL plugin in WordPress) and the server may both be redirecting. Turn off one of them.
- Preview address stops working: the temporary
stackstaging.compreview address can't load over HTTPS. Turn Force HTTPS off while you test on it.
Need help?
If something doesn't work as described, open a support ticket from your FimuroHost client area or message us on WhatsApp at 01818160926. Please include your domain name so we can check your account quickly.
Categories
Written by
FimuroHost Team
Technical Writer