Secure a website with SSL and HTTPS
Websites on Sheernox hosting get free SSL certificates from Let’s Encrypt, so they load over https:// with the padlock in the browser. A certificate can only be issued once the domain points to Sheernox.
Check a website’s certificates
Section titled “Check a website’s certificates”Open Websites, select the website and select Security in its navigation bar.
Every domain on the website is listed with its certificate marker 2 and expiry date. Self signed means the domain does not have a trusted certificate yet, and browsers show a security warning until it does. This is normal while the domain does not point to Sheernox. Once a trusted certificate is issued, the certificate and expiry date change to match it.
Hovering over the padlock beside a domain on the website’s Domains page shows the same information.
Request a free certificate
Section titled “Request a free certificate”Once the domain points to Sheernox:
-
On the website’s Security page, select the menu button (three dots) at the end of the domain’s row marker 4.
-
Select Request Let’s Encrypt certificate.
Request Let’s Encrypt certificate for mail. gets a certificate for the domain’s mail server name (mail. followed by your domain), which mail apps use to connect securely. Certificate details shows the current certificate.
Force HTTPS
Section titled “Force HTTPS”Switch on Force HTTPS marker 3 to send every visitor who types http:// to the secure https:// address. Turn it on only after the domain has a Let’s Encrypt or other trusted certificate, or visitors will see a security warning.
If your site says “not secure”
Section titled “If your site says “not secure””| Cause | Fix |
|---|---|
| The domain does not point to Sheernox yet | Point the domain to Sheernox, wait for the change to spread, then request the certificate |
| The name visitors use is not on the website | Add it on the website’s Domains page, then request a certificate for it |
The page loads some images or scripts over http:// |
Change those links to https://. In WordPress, check WordPress Address and Site Address under Settings > General |
Install your own certificate
Section titled “Install your own certificate”If you bought a certificate elsewhere, for example an extended validation certificate, install it yourself:
-
On the website’s Security page, select Install custom SSL marker 1.
-
Choose the Domain.
-
Paste the Certificate (CRT) and the Private key, or select Upload file for each.
-
Select Upload.
ModSecurity
Section titled “ModSecurity”The Security page also has ModSecurity, a web application firewall you can switch on for each domain. It blocks common attacks, but can occasionally block legitimate requests from some plugins or forms. If something stops working after you turn it on, switch it off for that domain and contact support.