Skip to content
  • Solutions
    By Role
    • For Developers
    • For Content Managers
    • For Agencies
    • For IT Admins
    • For Web Hosters
    • For Developers
    • For Content Managers
    • For Agencies
    • For IT Admins
    • For Web Hosters
    By Infrastructure
    • Overview
    • AWS
    • Microsoft Azure
    • Alibaba Cloud
    • Google Cloud Platform
    • Vultr
    • Overview
    • AWS
    • Microsoft Azure
    • Alibaba Cloud
    • Google Cloud Platform
    • Vultr
    • Digital Ocean
    • Linode
    • Upcloud
    • Oracle
    • OVH
    • Digital Ocean
    • Linode
    • Upcloud
    • Oracle
    • OVH
  • Product
    • Plesk Features
    • Plesk Editions
    • What’s new
    • Pricing
    • Roadmap
    • Lifecycle Policy
    • Extensions Catalogue
  • Pricing
  • Extensions
    Featured Extensions
    • SocialBee
    • WP Toolkit
    • Sitejet Builder for Plesk
    • SEO Toolkit
    • Joomla! Toolkit
    • Premium Email
    • Email Security
    • SocialBee
    • WP Toolkit
    • Sitejet Builder for Plesk
    • SEO Toolkit
    • Joomla! Toolkit
    • Premium Email
    • Email Security
    Bundles and packs:
    • Business and Collaboration Edition
    • WP pack
    • Hosting pack
    • Power pack
    • Language pack
    • Business and Collaboration Edition
    • WP pack
    • Hosting pack
    • Power pack
    • Language pack

    See all Extensions

  • For Partners
    • Plesk Contributor Program
    • Plesk Partner Program
    • Affiliate program
    • Plesk University
  • Help Center
    • Documentation
    • Professional Services
    • Support
    • Contact Us
    • Wiki
    • Forum
  • Plesk 360 login
  • Free Trial
  • Pricing
  • Solutions
    • By Role
      • For Developers
      • For Content Managers
      • For Agencies
      • For IT Admins
      • For Web Hosters
    • By Infrastructure
      • Overview
      • Plesk on Amazon Web Services (AWS & Lightsail)
      • Microsoft Azure
      • Alibaba Cloud
      • Google Cloud Platform
      • Vultr
      • DigitalOcean
      • Linode
      • UpCloud
      • Oracle
      • OVH
  • Products
  • Pricing
  • Extensions
    • Featured Extensions
      • SocialBee
      • WP Toolkit
      • Sitejet Builder for Plesk
      • SEO Toolkit
      • Joomla! Toolkit
      • Premium Email
      • Email Security
    • Bundles and packs:
      • Business and Collaboration Edition
      • WP pack
      • Hosting pack
      • Power pack
      • Language pack
      • See all Extensions
  • For Partners
    • Plesk Contributor Program
    • Plesk Partner Program
    • Affiliate Program
    • Plesk University
  • Help Center
    • Documentation
    • Professional Services
    • Support
    • Contact Us
    • Wiki
    • Forum
  • Plesk 360 login
  • Free Trial
  • Pricing
  • Solutions
    • By Role
      • For Developers
      • For Content Managers
      • For Agencies
      • For IT Admins
      • For Web Hosters
    • By Infrastructure
      • Overview
      • Plesk on Amazon Web Services (AWS & Lightsail)
      • Microsoft Azure
      • Alibaba Cloud
      • Google Cloud Platform
      • Vultr
      • DigitalOcean
      • Linode
      • UpCloud
      • Oracle
      • OVH
  • Products
  • Pricing
  • Extensions
    • Featured Extensions
      • SocialBee
      • WP Toolkit
      • Sitejet Builder for Plesk
      • SEO Toolkit
      • Joomla! Toolkit
      • Premium Email
      • Email Security
    • Bundles and packs:
      • Business and Collaboration Edition
      • WP pack
      • Hosting pack
      • Power pack
      • Language pack
      • See all Extensions
  • For Partners
    • Plesk Contributor Program
    • Plesk Partner Program
    • Affiliate Program
    • Plesk University
  • Help Center
    • Documentation
    • Professional Services
    • Support
    • Contact Us
    • Wiki
    • Forum
  • Plesk 360 login
  • Free Trial
Plesk 360 login
Free Trial

Knowledge Base

Securing Connections with the SSL It! Extension – Enhancing security of your websites

 
advanced website securityreseller guidesecuring connections with ssltls certificateswebsite managementwebsites and domains

Merely securing a website
with a valid SSL/TLS certificate from a trusted CA
is not enough to get all-round protection.
SSL is a complex technology,
which has a number of features (key encryption algorithm, OSCP stapling,
HSTS, and much more) that can
enhance the security of your website’s visitors and
improve your website performance.

Enabling these features can improve your websites’ search engine rankings:

  • “Redirect from http to https” sets up a permanent,
    SEO-safe 301 redirect from the insecure HTTP
    to the secure HTTPS version of the website and/or webmail.
  • HSTS prohibits web browsers from accessing the website
    via insecure HTTP connections.
  • OSCP makes the web server request the status of the website’s certificate
    (can be good, revoked, or unknown)
    from the CA instead of the visitor’s browser.

Caution: Before turning these features on,
ensure that your website can be accessed
via HTTPS without any issues.
Otherwise, visitors may have trouble accessing your website.

To enhance the security of your websites:

  1. Secure your website with a valid SSL/TLS certificate from a trusted CA.

  2. Go to Websites & Domains > your domain > SSL/TLS Certificates.

  3. Turn on “Redirect from http to https” if it is not already on.
    “Redirect from http to https” will be applied
    to both the website and webmail.

    Note: If your webmail is not secured with a valid SSL/TLS certificate
    or you do not have any webmail,
    clear the “Include webmail” checkbox.

  4. Enable HSTS:

    1. Turn on HSTS.

    2. Make sure that an SSL/TLS certificate
      that secures your website will be valid
      during the “Max-age” period.
      Do the same for subdomains and the webmail subdomain.
      Otherwise, if the SSL/TLS certificate expires earlier
      than the “Max-age” period and HSTS is turned on,
      visitors will not be able to access your website.

    3. If your subdomains are not secured with valid SSL/TLS certificates
      or you do not have any subdomains,
      clear the “Include subdomains” checkbox.

    4. If your webmail subdomain is not secured with a valid SSL/TLS certificate
      or you do not have any webmail,
      clear the “Include webmail” checkbox.

    5. Click Enable HSTS.

      Note: If your SSL/TLS certificate expires earlier
      than the “Max-age” period but you still want to use HSTS,
      we recommend that you turn on “Keep websites secured”.
      Then when…

Tweet
Share
Share
Email
0 Shares
Read the full article
Related Posts

Guide on Website Management

Read More »

Plesk Obsidian Preview: The Curtain Lifts

Read More »

Website Management Routine Basics

Read More »
Knowledge Base

IIS Web Server Settings – Directory Security Settings

Read More »

IIS Web Server Settings – Common Settings

Read More »

Optimizing Apache Web Server – Setting Up the Apache Restart Interval

Read More »

Securing Connections with the SSL It! Extension – Getting started with SSL It!

Read More »

Hosting Wiki

  • Encryption
  • Content Security Policy ( CSP )
  • Server Redundancy
  • Bare Metal Server
  • Oracle VM Server
  • Server Virtualization Software
  • Windows Server
  • HTTP/3
  • HTTP/2
  • Subdomain
  • Domain
  • Lighttpd
  • Web Server
  • DNS Server
  • SSL
  • Webmail
  • HTTP
X-twitter Linkedin Youtube Reddit Github
  • Product
  • Login
  • Pricing
  • Editions
  • For Partners
  • Partner Program
  • Contributor Program
  • Affiliate Program
  • Plesk University
  • Company
  • Blog
  • Careers
  • Events
  • About Plesk
  • Our Brand
  • Resources
  • User and Admin guides
  • Help Center
  • Migrate to Plesk
  • Contact Us
  • Hosting Wiki
  • Forum
  • Legal
  • Legal
  • Privacy Policy
  • Imprint

© 2025 WebPros International GmbH

Part of the WebPros®  Family