Moving your site to HTTPS with an SSL certificate

Published on 21/08/2026 Updated on 06/10/2026 87 views
Hébergement Web SSL HTTPS

Without HTTPS, browsers mark your site as not secure, form data travels in clear text and search ranking suffers. A free certificate takes a few minutes.

Why must my domain point here before a certificate can be issued?

A certificate is only issued if the certificate authority can verify the domain is yours, by querying the server it points to. While your A record does not designate your hosting address, issuing will fail.

Check that first:

  1. Open your domain in My services, DNS zone tab.
  2. Confirm the A record for the domain — name @ — points to the address shown under IP addresses on your hosting page.
  3. If you have just changed it, wait: propagation time depends on the TTL of the previous record.

How do I get a free SSL certificate for my site?

Open Plesk from the client area, go to Websites & Domains, then SSL/TLS Certificates, click Install under Let's Encrypt and finish with Get it free.

  1. From the client area, click Automatic connection to open Plesk.
  2. Open Websites & Domains, then SSL/TLS Certificates.
  3. Click Install under Let's Encrypt.
  4. Provide a contact e-mail address.
  5. Tick the option to include the www subdomain: without it, www.yourdomain.tld will show a certificate error.
  6. Also tick the webmail domain if you use the hosting mail service.
  7. Click Get it free.

The certificate is valid for three months and renews automatically. You have nothing to do, as long as your domain keeps pointing at the server.

How do I force every visitor onto HTTPS?

In Plesk, tick the permanent SEO-safe 301 redirect from HTTP to HTTPS under Websites & Domains > Hosting Settings.

An installed certificate is not enough: visitors arriving on http:// must be sent to https://.

In Plesk, open Websites & Domains > Hosting Settings and tick the permanent SEO-safe 301 redirect from HTTP to HTTPS. That is the clean method, understood by search engines.

If your application manages its own addresses — WordPress, PrestaShop, Joomla — also switch its base URL to https:// in its settings, otherwise it will keep generating plain links.

Why is the padlock still crossed out even with a certificate?

Your page is served over HTTPS but the browser still warns? It is almost always mixed content: an image, a stylesheet or a script still requested over http://.

  1. Open the browser console with F12, Console tab.
  2. The offending resources are listed there with their full address.
  3. Fix them in your theme, your articles or your database. On a CMS, a search-and-replace extension does this in one pass.

What do the most common certificate errors mean?

Most of them come from a name missing from the certificate — usually www — or from a domain that no longer points at the server.

  • "The certificate does not match the site name": you are reaching the site by a name absent from the certificate, usually www. Reissue the certificate including that subdomain.
  • "Certificate expired": automatic renewal failed, almost always because the domain no longer points at the server. Fix the DNS zone, then issue again.
  • Issuing fails immediately: check the A record, and that no redirect is diverting the verification requests.
  • The site still shows over HTTP despite the redirect: clear your browser cache, and your CMS cache.

Does my certificate cover my subdomains as well?

The certificate covers the names you ticked when issuing it. If you later add a subdomain — blog.yourdomain.tld for instance — reissue the certificate to include it, or request a dedicated one from the same page.

Was this article helpful?