How to Force HTTPS in Joomla
Install and verify a valid TLS certificate first
Joomla's Force HTTPS setting assumes the web server can already serve the site over HTTPS. Current Joomla Global Configuration documentation explicitly notes that HTTPS must be enabled on the server before using the option. Install a valid certificate through your hosting provider or server tooling, then confirm that an https:// URL loads without a certificate warning.
Test important pages over HTTPS before forcing redirects
Open the frontend, Administrator login, forms, extension routes, downloads, and other important pages directly with https://. Fix certificate-chain, hostname, proxy, or mixed-content problems first. Forcing HTTPS before the secure site works correctly can lock administrators out or turn a manageable certificate problem into a redirect loop.
Enable Force HTTPS in Global Configuration
In Joomla Administrator, go to System → Setup → Global Configuration and open the Server tab. Locate Force HTTPS. Joomla documents the setting as forcing selected site areas to use HTTPS and secure cookies. For a modern public site, select Entire Site when all frontend and Administrator traffic should be encrypted, then save the configuration.
Understand the Administrator Only option
Joomla also supports forcing HTTPS only for the Administrator area. That can be useful in specialized configurations, but it leaves frontend traffic eligible for HTTP. Sites with logins, forms, account pages, or other sensitive frontend activity generally benefit from HTTPS across the entire site. Choose intentionally based on the site's architecture.
Avoid competing redirect rules
Hosting panels, Apache or Nginx rules, reverse proxies, load balancers, and CDNs can also redirect HTTP to HTTPS. Multiple layers are not automatically safer and can create loops when they disagree about the original request scheme. Prefer one clearly understood redirect strategy and make sure proxy headers and Joomla's HTTPS detection are configured correctly.
Check extensions and hard-coded HTTP resources
After enabling HTTPS, browse representative pages and inspect the browser console and Network panel. Replace hard-coded http:// references to scripts, stylesheets, images, fonts, API endpoints, or canonical URLs where they cause mixed content or incorrect redirects. Third-party integrations may also need their callback or webhook URLs updated.
Verify the public result
Request an http:// page and confirm it redirects to the corresponding https:// URL without looping or losing the path and query string. Check the final certificate, secure cookies, canonical host, frontend, Administrator, login, and checkout or account workflows. Only after the entire path is correct should HTTPS enforcement be considered complete.
Need More Help with Joomla?
Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.
Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.
QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.