What is SSL?
SSL is a way to keep the link between a visitor and your site private. When it works, the address starts with https:// and the browser shows a padlock. It matters a lot for a shop, because customers type names and card details.
Magento is software for online shops. It stores its own web address in its settings. If the settings still say http://, the padlock may not appear, even when a certificate is installed.
Take a backup of your store before you change any settings.
Step 1: Check that a certificate is installed
- Type your site address with
https://in front, in your browser. - If the browser warns you that the site is not safe, the certificate is missing, out of date or for another name.
- Check the SSL area in your hosting control panel. Ask Hostvento support if you need help to install or renew a certificate.
Fix this first. Magento settings cannot help without a good certificate.
Step 2: Set secure web addresses in Magento
- Log in to your Magento admin area.
- Click Stores, then Configuration.
- Click General, then Web.
- Open Base URLs. Change Base URL to start with
https://. - Open Base URLs (Secure). Change Secure Base URL to start with
https://. - Set Use Secure URLs on Storefront to Yes.
- Set Use Secure URLs in Admin to Yes.
- Click Save Config.
Changing a base address wrongly can lock you out of the admin area. Double-check the spelling before you save.
Step 3: Clear the cache
- Click System, then Cache Management.
- Click Flush Magento Cache.
Step 4: Look for mixed content
Mixed content means a secure page that loads a picture or script from an http:// address. The browser then removes the padlock. Press F12 in your browser and open the Console tab. It names the files that load insecurely. Change their links to https://.
Step 5: Add a redirect
A redirect sends visitors from http:// to https:// by themselves. Many control panels have a "Force HTTPS" switch. Ask Hostvento support if you cannot find it.
Quick recap
- First check that a valid certificate exists.
- Set both base URLs to https in Stores, Configuration, Web.
- Turn on secure URLs for storefront and admin.
- Flush the cache.
- Fix mixed content and add a redirect.