Every Windows Hosting plan includes a free wildcard SSL certificate from Let's Encrypt, covering your domain and its subdomains, and it renews automatically. Getting a site fully onto HTTPS takes three steps: activate the certificate, send visitors to HTTPS, and make sure your application itself behaves securely.
Step 1: Activate the certificate
Your domain must use our nameservers (ns1.stackdns.com and ns2.stackdns.com) and the change must have taken effect. Then:
- Log in to your FimuroHost client area at https://app.fimurohost.com.
- Open Services and select your Windows Hosting plan (Starter, Premium or Business).
- Click Login to Control Panel. StackCP opens for that website, already signed in.
- In the Security section, click SSL/TLS.
- Click Activate Free SSL next to your domain.
- Allow up to 30 minutes for the certificate to be served everywhere.
Full details and troubleshooting: How to Activate the Free SSL Certificate in StackCP. If you bought a certificate elsewhere, see Install a Third-Party SSL Certificate in StackCP.
Open https://yourdomain.com in a private window and check the padlock before going further.
Step 2: Redirect HTTP to HTTPS
Use one of these methods, not both.
Option A: The Force HTTPS switch
If the SSL/TLS page in StackCP shows an Enable Force HTTPS option for your site, turning it on is the simplest approach and needs no code.
Option B: A rule in web.config
Add this inside <system.webServer> in the web.config in your site root:
<rewrite> <rules> <rule name="Force HTTPS" stopProcessing="true"> <match url="(.*)" /> <conditions> <add input="{HTTPS}" pattern="^OFF$" /> </conditions> <action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" /> </rule> </rules> </rewrite>
If this causes a “too many redirects” error, IIS is seeing already-secure requests as HTTP because HTTPS is handled in front of it. Replace the condition with <add input="{HTTP_X_FORWARDED_PROTO}" pattern="^http$" />. More redirect examples, including www and non-www, are in URL Rewrite Rules in web.config.
Note: the temporary stackstaging.com preview address doesn't support HTTPS. With a redirect in place it will jump to your real domain, which is expected.
Step 3: Add HSTS (optional, recommended)
HTTP Strict Transport Security tells browsers to use HTTPS for your domain automatically, even if someone types http://. Only add it once HTTPS works on every page and subdomain you use:
<system.webServer> <httpProtocol> <customHeaders> <add name="Strict-Transport-Security" value="max-age=31536000" /> </customHeaders> </httpProtocol> </system.webServer>
Start with a short value such as max-age=300 (5 minutes) for testing, then raise it to one year. Browsers remember HSTS, so if you later remove SSL, returning visitors can't reach the site until the time runs out.
Step 4: Make your ASP.NET application HTTPS-aware
Secure cookies
Mark cookies so they are only sent over HTTPS and can't be read by JavaScript:
<system.web> <httpCookies requireSSL="true" httpOnlyCookies="true" /> <authentication mode="Forms"> <forms loginUrl="~/Account/Login" requireSSL="true" timeout="60" /> </authentication> </system.web>
Only set requireSSL after HTTPS is working, otherwise logins will silently fail on http://. Keep your existing <forms> attributes and just add requireSSL.
Fix mixed content
A padlock warning after activating SSL usually means a page loads images, CSS or scripts over http://. Search your master pages, layouts (_Layout.cshtml, Site.Master), Classic ASP includes and database content for http:// and change them to https:// or root-relative paths like /images/logo.png. See Fix “Not Secure” Warnings Caused by Mixed Content.
Checking for HTTPS in code
If your code checks Request.IsSecureConnection (ASP.NET) or Request.ServerVariables("HTTPS") (Classic ASP) and gets false on pages that clearly load over HTTPS, check the X-Forwarded-Proto request header as well:
bool isHttps = Request.IsSecureConnection || string.Equals(Request.Headers["X-Forwarded-Proto"], "https", StringComparison.OrdinalIgnoreCase);
Outgoing HTTPS calls from your code
Payment gateways and APIs require TLS 1.2 or newer. Apps targeting .NET Framework 4.7 or later use the operating system's modern defaults automatically; older targets may fail with “Could not create SSL/TLS secure channel”. Set <httpRuntime targetFramework="4.8" />, or add ServicePointManager.SecurityProtocol |= SecurityProtocolType.Tls12; at startup.
Common problems
- No “Activate” button, or activation fails. The domain isn't using our nameservers yet.
- Redirect loop. Both the StackCP switch and a
web.configrule are on, or the rule needs theX-Forwarded-Protocondition. - Users can't stay logged in after enabling requireSSL. Some pages are still on
http://. Add the redirect. - Certificate warning on
mail.orftp.hosts. Those services have their own certificates; see Fixing Certificate Name Mismatch Email Errors.
Need help?
If something doesn't work as described, open a support ticket from your client area or message us on WhatsApp at 01818160926. Tell us your domain name and the exact error message, and we will take it from there.
Categories
Written by
FimuroHost Team
Technical Writer