4 min read Sep 26, 2026

SSL and HTTPS on Windows Hosting: Activate, Redirect and Secure Cookies

Activate the free wildcard SSL on Windows Hosting, redirect HTTP to HTTPS with web.config, add HSTS and make ASP.NET cookies and links HTTPS-only.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

Every Windows Hosting plan includes a free wildcard SSL certificate from Let's Encrypt, covering your domain and its subdomains, and it renews automatically. Getting a site fully onto HTTPS takes three steps: activate the certificate, send visitors to HTTPS, and make sure your application itself behaves securely.

Step 1: Activate the certificate

Your domain must use our nameservers (ns1.stackdns.com and ns2.stackdns.com) and the change must have taken effect. Then:

  1. Log in to your FimuroHost client area at https://app.fimurohost.com.
  2. Open Services and select your Windows Hosting plan (Starter, Premium or Business).
  3. Click Login to Control Panel. StackCP opens for that website, already signed in.
  4. In the Security section, click SSL/TLS.
  5. Click Activate Free SSL next to your domain.
  6. Allow up to 30 minutes for the certificate to be served everywhere.

Full details and troubleshooting: How to Activate the Free SSL Certificate in StackCP. If you bought a certificate elsewhere, see Install a Third-Party SSL Certificate in StackCP.

Open https://yourdomain.com in a private window and check the padlock before going further.

Step 2: Redirect HTTP to HTTPS

Use one of these methods, not both.

Option A: The Force HTTPS switch

If the SSL/TLS page in StackCP shows an Enable Force HTTPS option for your site, turning it on is the simplest approach and needs no code.

Option B: A rule in web.config

Add this inside <system.webServer> in the web.config in your site root:

<rewrite>
  <rules>
    <rule name="Force HTTPS" stopProcessing="true">
      <match url="(.*)" />
      <conditions>
        <add input="{HTTPS}" pattern="^OFF$" />
      </conditions>
      <action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" />
    </rule>
  </rules>
</rewrite>

If this causes a “too many redirects” error, IIS is seeing already-secure requests as HTTP because HTTPS is handled in front of it. Replace the condition with <add input="{HTTP_X_FORWARDED_PROTO}" pattern="^http$" />. More redirect examples, including www and non-www, are in URL Rewrite Rules in web.config.

Note: the temporary stackstaging.com preview address doesn't support HTTPS. With a redirect in place it will jump to your real domain, which is expected.

Step 3: Add HSTS (optional, recommended)

HTTP Strict Transport Security tells browsers to use HTTPS for your domain automatically, even if someone types http://. Only add it once HTTPS works on every page and subdomain you use:

<system.webServer>
  <httpProtocol>
    <customHeaders>
      <add name="Strict-Transport-Security" value="max-age=31536000" />
    </customHeaders>
  </httpProtocol>
</system.webServer>

Start with a short value such as max-age=300 (5 minutes) for testing, then raise it to one year. Browsers remember HSTS, so if you later remove SSL, returning visitors can't reach the site until the time runs out.

Step 4: Make your ASP.NET application HTTPS-aware

Secure cookies

Mark cookies so they are only sent over HTTPS and can't be read by JavaScript:

<system.web>
  <httpCookies requireSSL="true" httpOnlyCookies="true" />
  <authentication mode="Forms">
    <forms loginUrl="~/Account/Login" requireSSL="true" timeout="60" />
  </authentication>
</system.web>

Only set requireSSL after HTTPS is working, otherwise logins will silently fail on http://. Keep your existing <forms> attributes and just add requireSSL.

Fix mixed content

A padlock warning after activating SSL usually means a page loads images, CSS or scripts over http://. Search your master pages, layouts (_Layout.cshtml, Site.Master), Classic ASP includes and database content for http:// and change them to https:// or root-relative paths like /images/logo.png. See Fix “Not Secure” Warnings Caused by Mixed Content.

Checking for HTTPS in code

If your code checks Request.IsSecureConnection (ASP.NET) or Request.ServerVariables("HTTPS") (Classic ASP) and gets false on pages that clearly load over HTTPS, check the X-Forwarded-Proto request header as well:

bool isHttps = Request.IsSecureConnection ||
    string.Equals(Request.Headers["X-Forwarded-Proto"], "https", StringComparison.OrdinalIgnoreCase);

Outgoing HTTPS calls from your code

Payment gateways and APIs require TLS 1.2 or newer. Apps targeting .NET Framework 4.7 or later use the operating system's modern defaults automatically; older targets may fail with “Could not create SSL/TLS secure channel”. Set <httpRuntime targetFramework="4.8" />, or add ServicePointManager.SecurityProtocol |= SecurityProtocolType.Tls12; at startup.

Common problems

  • No “Activate” button, or activation fails. The domain isn't using our nameservers yet.
  • Redirect loop. Both the StackCP switch and a web.config rule are on, or the rule needs the X-Forwarded-Proto condition.
  • Users can't stay logged in after enabling requireSSL. Some pages are still on http://. Add the redirect.
  • Certificate warning on mail. or ftp. hosts. Those services have their own certificates; see Fixing Certificate Name Mismatch Email Errors.

Need help?

If something doesn't work as described, open a support ticket from your client area or message us on WhatsApp at 01818160926. Tell us your domain name and the exact error message, and we will take it from there.

FimuroHost Team

Written by

FimuroHost Team

Technical Writer