Glossary

How to Enable HTTPS on Your Website and Force SSL

Learn how to install an SSL certificate, enable HTTPS on your website, and force a redirect so no visitor ever lands on the insecure HTTP version.

An adult man immersed in reading by the window in Madrid. Warm, focused study atmosphere.

To enable HTTPS on your website you need to install an SSL certificate on your server or hosting account, then force a redirect from HTTP to HTTPS using a rule in .htaccess or your CMS settings. The entire process can be completed in under 15 minutes with a free Let's Encrypt certificate.

This guide covers each step clearly: from obtaining the certificate to confirming that no HTTP request slips through unredirected.

Why You Need HTTPS (and What Happens Without It)

HTTPS encrypts the communication between a visitor's browser and your server. Without it, data travels in plain text and can be intercepted.

The concrete consequences of skipping HTTPS include:

  • "Not Secure" browser warning in Chrome, Firefox, and Safari — an immediate trust killer.
  • SEO penalty — Google has used HTTPS as a ranking signal since 2014.
  • Exposed form data and payment information — legal and reputational risk.
  • Modern browser blocks on pages with HTTP forms or mixed content.

An SSL certificate is no longer optional — it's the baseline expectation from both users and search engines.

Types of SSL Certificates: Which One to Choose

Before enabling HTTPS, pick the certificate type that fits your situation:

Type Validation Best for Approximate cost
Let's Encrypt (DV) Domain Informational sites, blogs, small businesses Free
DV (Domain Validation) Domain Small to mid-sized projects $0–$70 USD/year
OV (Organization Validation) Company Online stores, corporate portals $70–$200 USD/year
EV (Extended Validation) Extended Banking, high-volume e-commerce $200–$600 USD/year

For most small business websites, Let's Encrypt is the right answer: it's free, automatic, and trusted by every major browser.

How to Install an SSL Certificate in cPanel (Let's Encrypt)

Most hosting providers include Let's Encrypt directly in cPanel. Here's how to activate it:

  1. Log in to your cPanel.
  2. Go to the Security section and click "SSL/TLS" or "Let's Encrypt SSL" (some providers label it AutoSSL).
  3. Select the domain (and the www subdomain) for which you want the certificate.
  4. Click "Install" or "Run AutoSSL". The process takes 1–2 minutes.
  5. When finished, open https://yourdomain.com in a browser and confirm the padlock appears.

If your hosting doesn't use cPanel, look for a "SSL", "Certificates", or "Security" section in your control panel — most providers offer an equivalent one-click button.

Manual Installation via CLI (Certbot)

If you have SSH access to a VPS or dedicated server, install the certificate with Certbot:

sudo certbot --apache -d yourdomain.com -d www.yourdomain.com

Certbot configures Apache or Nginx automatically and schedules automatic renewal. The certificate expires every 90 days but renews itself.

How to Force HTTPS: Redirect All HTTP Traffic

Installing the certificate enables HTTPS but does not remove HTTP access. You need a permanent (301) redirect so visitors and Google's crawlers always use the secure version.

Option 1: .htaccess Rule (Apache)

Edit the .htaccess file in your site's root and add at the top:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

This rule catches every HTTP request and redirects it to its HTTPS equivalent with a 301 (permanent) status code.

Option 2: WordPress Settings

In Settings → General, change both URLs (WordPress Address and Site Address) to start with https://. Then add the .htaccess rule above, or use the Really Simple SSL plugin, which handles everything automatically.

Option 3: Nginx Server Block

server {
    listen 80;
    server_name yourdomain.com www.yourdomain.com;
    return 301 https://$host$request_uri;
}

Verifying That HTTPS Is Working Correctly

After enabling HTTPS and the redirect, check these points:

  • Padlock in the browser: must appear on every page, including internal pages.
  • No mixed content: open the browser developer tools (F12 → Console) to catch images, scripts, or fonts still loading over HTTP. Update those URLs to HTTPS.
  • SSL Labs tool (ssllabs.com/ssltest): analyzes your certificate configuration and gives you a grade (A, B, or lower) with specific recommendations.
  • Redirect check: type http://yourdomain.com in the browser and confirm it automatically switches to https://.

If you need help configuring SSL in a complex environment or on a server without a control panel, the team at elenlace.com provides specialist hosting technical support.

Common Mistakes When Enabling HTTPS

Here are the most frequent issues and how to fix them:

  • Mixed content: resources still loading from HTTP URLs. In WordPress, use a search-and-replace plugin (such as Better Search Replace) to update all URLs in the database.
  • Certificate issued for the wrong domain: the certificate covers yourdomain.com but not www.yourdomain.com, or vice versa. Always include both variants when installing.
  • Redirect loop: happens when the .htaccess rule conflicts with server settings. Check that RewriteEngine On isn't duplicated and that no other redirect block conflicts.
  • Expired certificate: Let's Encrypt lasts 90 days. If auto-renewal fails, the site shows a security error. Confirm that AutoSSL or the Certbot cron job is active and scheduled.

Key Takeaways

  • HTTPS is mandatory for SEO, user trust, and data security.
  • Let's Encrypt provides free, automatic SSL certificates trusted by all major browsers.
  • Installing the certificate activates HTTPS, but you must add a 301 redirect to eliminate HTTP access.
  • After enabling HTTPS, check for mixed content so the padlock appears on every page.
  • Use SSL Labs and the browser console to diagnose any remaining issues.

Is your site still showing "Not Secure"? Visit elenlace.com and a specialist will help you activate HTTPS, fix mixed content, and get everything working in one service.

FAQ

Does HTTPS slow down my website?

The impact is minimal and virtually unnoticeable on modern servers. In fact, HTTPS is a prerequisite for HTTP/2 and HTTP/3, protocols that actually speed up page load times compared to HTTP/1.1.

Does my Let's Encrypt certificate renew automatically?

Yes, as long as the renewal process is active. In cPanel with AutoSSL, renewal is fully automatic. With Certbot on your own server, the installer schedules a cron job that renews the certificate 30 days before it expires.

Do I need HTTPS if my site doesn't sell anything or have forms?

Yes. Google marks any site without HTTPS as "Not Secure," which reduces visitor trust and can hurt your search rankings, regardless of whether the site handles sensitive data.

Can I have HTTPS on a subdomain separately from the main domain?

Yes. You can issue a certificate specifically for blog.yourdomain.com or any subdomain. Wildcard certificates (*.yourdomain.com) cover all first-level subdomains under a single certificate, though they aren't available for free from every provider.

Find more guides on security and hosting configuration in our hosting glossary section.

Further reading

Other providers and guides worth comparing:

← All