SSL is installed on the web server or in the hosting panel. A PHP script does not issue a certificate by itself. It must open over https, handle cookies correctly, and avoid loading images or scripts over http; otherwise you get mixed content and strange login behavior.
Let's Encrypt is the standard now, both in hosting panels and on a VDS through Certbot. A paid certificate is rarely needed unless EV or a special wildcard scenario is required.
Shared hosting
The domain panel usually has an SSL / HTTPS section. Enable certificate issuance for the domain and www if needed. Wait for issuance; DNS must already point to this hosting, otherwise validation fails.
Enable http to https redirect in the panel if there is a checkbox. If not, use .htaccess on Apache:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
On Nginx, the redirect is written in the port 80 server block. ISPmanager often does this automatically.
VDS: Certbot and Nginx/Apache
Typical Nginx path:
certbot --nginx -d example.com -d www.example.com
For Apache, use certbot --apache. Before that, the vhost on port 80 must serve the site with the correct server_name. Otherwise Certbot has nowhere to write SSL directives.
Check renewal: certbot renew --dry-run. The certificate lasts 90 days; without renewal the site suddenly becomes "not secure" in a quarter. Server stack: Nginx + PHP-FPM, ports: firewall (443 open from outside).
What to adjust in the script
- Site URL in settings with
https://. - Canonical links and redirects in the admin area, if present.
- Database content with old http image URLs, at least in critical places.
If the admin area opens after SSL but styles disappear, search the page source for http:// pointing to your own assets. Browsers block mixed content on https pages.
Cookies with the Secure flag will not work on plain http; after moving to https, login usually becomes more stable. Local https debugging: HTTPS on local host.
www and bare domain
The certificate must cover every name you use, or one canonical name must redirect to the other. Otherwise some users land on a name without SSL. Issue SAN for both or keep a strict redirect to one name before checking the certificate.
Proxy and "HTTPS is already somewhere"
If Cloudflare or a load balancer terminates SSL before the server, the backend may see http. Then the script may generate http links. Check X-Forwarded-Proto and Cloudflare HTTPS settings. A redirect loop across CF, origin, and CF is a classic failure.
Issuance errors
Certificate did not issue:
- DNS does not point to this server yet;
- port 80 is closed by firewall, so HTTP-01 challenge fails;
- another vhost or host placeholder responds for the domain;
- Let's Encrypt attempt limit was hit, so wait and stop clicking.
If "certificate exists but browser warns", it is expired, issued for a wrong name, or served without the intermediate chain. Check not only the certificate itself but the chain.
Post-enable checklist
- Homepage opens over https without warning.
- Redirect from http works once, without a loop.
- Account area, cart, and payment have no mixed content.
- Admin area and file upload work.
- Cron and external webhooks point to https URLs.
Fresh script installation: installation. Migration to a host that already had SSL: migration. Server choice: hosting or VDS.
HSTS
HSTS makes sense when https works reliably. Enable it too early and break the certificate, and client browsers will remember "https only" even if you temporarily roll back to http. On a new project, postpone HSTS. On a mature site, enable it with a reasonable max-age.
Redirects and www
Choose a canonical host: with www or without. The certificate must cover both or the redirect must land on the name inside the certificate. Otherwise some users see a warning. The script's "site URL" field must match the canonical host, or email links will be generated incorrectly.
Payments and callbacks
Payment providers often require https for return URLs and webhooks. After enabling SSL, update URLs in the payment dashboard. Old http callbacks may stop being accepted. Check a test payment after deployment, not just the lock icon in the address bar.
Intermediate certificates
The browser complains while openssl from the server looks fine: mobile clients sometimes cannot build the chain. Make sure fullchain is served (Certbot usually uses fullchain.pem). Panels sometimes install only the leaf certificate without intermediates.
Local debugging before production
It is worth running the account area once on local https: local HTTPS, stack: MicroServer. You will catch mixed content before production.
Renewal and migration
When moving to a new VDS, the certificate from the old server does not migrate by itself. Issue it again after DNS. While DNS still points elsewhere, you can test the new server through the hosts file on http, then switch DNS and run certbot. The firewall must allow 80 for challenge: firewall. Web on VDS: Nginx.
If SSL causes a redirect loop, look for duplicate forcing: panel, script, and Cloudflare "Always HTTPS". Leave one layer. 500 errors are checked separately: 500.
Browser check and openssl
Do not look only at the lock icon. Open certificate details: name, dates, issuer. From the server:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates -subject
If the subject is not your domain, a wrong vhost responds on the IP. Fix server_name and server block order in Nginx/Apache, not the script. After migrating a domain away from another host, the old certificate on the old IP no longer matters.
Certificate expiry monitoring next to uptime prevents sudden "site not secure" complaints on Monday: monitoring. Backup before changing panels or redirects by habit: backup.
FAQ
How to install ssl on php site?
Certificate on the host plus redirect. In the script, check that links did not remain on http.
How long does “SSL on a PHP Site” take?
About 6 minutes to read. In practice it depends on your hosting and database setup.
Do I need a dedicated server?
For most scripts, shared hosting or a VDS with PHP and MySQL is enough. See the VDS section and PHP/MySQL requirements.
How to install a php script on hosting?
See the related manual for this query. how to install a php script on hosting
Php mysql requirements for a script?
See the related manual for this query. php mysql requirements for a script