Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to fix Magento when SSL is not working

This guide helps you find out why your Magento store does not show the padlock or does not load over https, and how to fix it.

CMS and Apps2 min read13 steps

What is SSL?

SSL is a way to keep the link between a visitor and your site private. When it works, the address starts with https:// and the browser shows a padlock. It matters a lot for a shop, because customers type names and card details.

Magento is software for online shops. It stores its own web address in its settings. If the settings still say http://, the padlock may not appear, even when a certificate is installed.

Take a backup of your store before you change any settings.

Step 1: Check that a certificate is installed

  1. Type your site address with https:// in front, in your browser.
  2. If the browser warns you that the site is not safe, the certificate is missing, out of date or for another name.
  3. Check the SSL area in your hosting control panel. Ask Hostvento support if you need help to install or renew a certificate.

Fix this first. Magento settings cannot help without a good certificate.

Step 2: Set secure web addresses in Magento

  1. Log in to your Magento admin area.
  2. Click Stores, then Configuration.
  3. Click General, then Web.
  4. Open Base URLs. Change Base URL to start with https://.
  5. Open Base URLs (Secure). Change Secure Base URL to start with https://.
  6. Set Use Secure URLs on Storefront to Yes.
  7. Set Use Secure URLs in Admin to Yes.
  8. Click Save Config.

Changing a base address wrongly can lock you out of the admin area. Double-check the spelling before you save.

Step 3: Clear the cache

  1. Click System, then Cache Management.
  2. Click Flush Magento Cache.

Step 4: Look for mixed content

Mixed content means a secure page that loads a picture or script from an http:// address. The browser then removes the padlock. Press F12 in your browser and open the Console tab. It names the files that load insecurely. Change their links to https://.

Step 5: Add a redirect

A redirect sends visitors from http:// to https:// by themselves. Many control panels have a "Force HTTPS" switch. Ask Hostvento support if you cannot find it.

Tip: Locked out after changing the address? Open a ticket at https://secure.hostvento.com/submitticket.php. Support can help you correct the base URL in the database.

Quick recap

  • First check that a valid certificate exists.
  • Set both base URLs to https in Stores, Configuration, Web.
  • Turn on secure URLs for storefront and admin.
  • Flush the cache.
  • Fix mixed content and add a redirect.