← All articles
HOSTING GUIDE

HTTPS and certificates: what must keep working after setup

The lock icon in the address bar depends on the domain, server and a valid certificate working together. HTTPS protects traffic between a browser and a website. It does not by itself secure the application or ensure that stored data is handled correctly.

Illustration of a secure website connection and certificate

The certificate must match the address

A certificate establishes the server's identity for the listed domains and enables an encrypted connection. When choosing hosting, ask whether setup and automatic renewal cover the versions with and without www, as well as any other subdomains you use. If the website moves to another server, test the secure connection in the new environment before changing DNS.

Enabling HTTPS on the home page is not enough

After deployment, open inner pages, forms and the administration area too. Links to your own files should all use secure addresses, or the browser may report mixed content. Redirect insecure addresses to secure ones and choose one primary form of the address so visitors do not end up on different versions of the same site.

Monitoring is part of ongoing operation

Check who is responsible for certificate renewal and how you will be alerted if it fails. After any change to the domain, proxy or CDN, test the connection in an ordinary browser. MDN explains the certificate's role in verifying the server and protecting traffic.

In the hosting control panel, make sure you can see the expiry date and automatic renewal status. Prepare a complete list if you use several domains. An address used only for customer support or an old subdomain is easy to overlook. Open those less frequently used versions after configuration changes too. That way you find an error before a visitor reports it.

Practical question: Who will receive an alert if automatic renewal fails during a holiday? Assign that responsibility explicitly.

More articles