cPanelOps · Hosting guides for site operators
cPanelOpsv2.2.0
Plain-English cPanel help from the team behind FirstResponderHost
26 guides live
CpanelOps / PageOps

Home › Guides

Security

AutoSSL and forcing HTTPS on cPanel without a redirect loop

Get a free certificate issued, send every visitor to the secure address, and avoid the "too many redirects" trap.

Every site should load over HTTPS. Browsers mark plain HTTP pages as "Not secure", logins and forms are exposed without it, and ad and analytics scripts expect it. On cPanel hosting the certificate is free and mostly automatic. The part that trips people up is the redirect.

Step 1: make sure a certificate is installed

In cPanel, open SSL/TLS Status. Each address on the account is listed with a padlock: green for a valid certificate, red for none. Tick the ones that are red and press Run AutoSSL. Issuing usually takes a few minutes.

If AutoSSL fails for a name, the page says why. The usual reasons:

  • The name does not point at this server. AutoSSL proves you control the domain by fetching a test file from it. If the DNS record for www or mail points elsewhere, that name fails. Fix the DNS record, or exclude that name from AutoSSL.
  • Something blocks the test file. The check requests an address under /.well-known/. A rule in .htaccess that redirects everything, or password protection on the whole site, can stop it. Exempt that folder.
  • The domain was added minutes ago. DNS changes need time to spread. Try again in an hour.

Step 2: redirect HTTP to HTTPS

The simple way: open Domains in cPanel and switch on Force HTTPS Redirect for the domain. The switch only becomes available once a valid certificate is in place.

If you prefer to do it by hand, or your cPanel version lacks the switch, add this near the top of .htaccess in public_html:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Use one method, not both.

The redirect loop, and why it happens

If the browser reports "too many redirects" right after you add the rule, the site is almost certainly behind a proxy such as Cloudflare that is set to connect to your server over plain HTTP (Cloudflare calls this mode "Flexible"). The visitor arrives over HTTPS, the proxy fetches the page from your server over HTTP, your server sees an insecure request and redirects, and round it goes.

VisitorbrowserProxye.g. CloudflareYour servercPanel hosting1. HTTPS2. plain HTTP3. "This is not secure, go to HTTPS" … and the visitor starts again at step 1
Why the loop happens: the proxy talks to your server over plain HTTP, so the server never sees a secure request.

The right fix is at the proxy: set its SSL mode so it connects to your server over HTTPS and checks the certificate (Cloudflare's "Full (strict)"). Your server already has a valid certificate from Step 1, so this works straight away and the traffic is encrypted the whole way.

Step 3: clean up mixed content

After the redirect, a page can still show a warning if it loads an image or script from an http:// address. Open the browser's developer tools, look at the Console tab, and it lists each insecure item. Change those addresses to https://. In WordPress, also set both site addresses under Settings > General to the https:// version; old addresses saved inside posts can be updated with a search-and-replace tool.

About HSTS

HSTS is a header that tells browsers to refuse plain HTTP for your domain for a set length of time. It is worth having, but add it last, once every address on the domain has loaded over HTTPS without warnings for a week or two. A browser that has seen the header will not let visitors click through a certificate problem, so a mistake is hard to undo. When you are ready:

Header always set Strict-Transport-Security "max-age=31536000"

Renewal

AutoSSL renews certificates by itself before they expire. It can only do that while the domain still points at the server and the check address is reachable, so if you later move DNS or add a blanket redirect, look at SSL/TLS Status again afterwards.

Common questions

Is the free certificate as good as a paid one?

For encryption, yes. A free domain-validated certificate protects the connection exactly as a paid one of the same type does, and browsers show the same padlock. Paid certificates add things such as a warranty or validation of the company's identity, which most small sites do not need.

Should www and non-www both have a certificate?

Yes. A visitor who types the other form of the address meets the certificate check before any redirect can happen, so both names must be covered. AutoSSL includes both as long as both point at the server.

My site is behind Cloudflare. Do I still need AutoSSL on the server?

You do. The proxy's certificate covers the visitor-to-proxy half of the journey. Without a certificate on your server the proxy-to-server half travels unencrypted, and the stricter proxy modes will refuse to connect at all.

How do I check when the certificate expires?

Click the padlock in the browser's address bar and open the certificate details, or look at SSL/TLS Status in cPanel, which lists the expiry date for each name. AutoSSL certificates are short-lived on purpose and are replaced well before that date.

Spotted a mistake, or a step that has changed?

cPanel's screens differ a little between versions and hosts. Tell us at info@firstresponderhost.com and we will correct the guide.

More guides