How to Redirect HTTP to HTTPS on a Joomla Website

After a Joomla site has a valid TLS certificate and works correctly over HTTPS, redirect HTTP requests to HTTPS so visitors consistently use the encrypted version. The safest setup uses one authoritative redirect layer, preserves the requested path and query string, and is tested before stronger browser policies such as HSTS are introduced.

Verify HTTPS works before forcing it

  1. Open the HTTPS home page and several deep URLs.
  2. Confirm the certificate is valid for every hostname you intend to serve.
  3. Test Administrator login and important forms.
  4. Resolve mixed-content or certificate errors before enforcing the redirect.

If HTTPS itself is broken, a forced redirect can make the entire site inaccessible.

Choose one place to enforce HTTPS

You can commonly enforce HTTPS at the CDN/load balancer, hosting platform, or origin web server. Use the layer that reliably sees the original request and is under your control. Apache, Nginx, IIS, and managed hosts use different configuration methods.

Avoid simultaneously enabling unrelated HTTPS redirects at the CDN, web server, Joomla configuration, and an extension. Multiple rules are unnecessary and can create loops behind proxies.

Preserve the hostname, path, and query string correctly

The HTTP version of a page should normally redirect to the corresponding HTTPS URL, not just the home page. If you are also normalizing www versus non-www, design the rules so the request reaches the preferred HTTPS hostname in as few hops as practical.

Account for reverse proxies and CDNs

If TLS terminates at a proxy, the connection from the proxy to the origin may be HTTP even though the visitor used HTTPS. Configure the proxy to send trustworthy scheme information and configure the origin/Joomla environment to interpret it correctly. Otherwise the origin can repeatedly redirect an already-secure visitor back to HTTPS.

Test the redirect before considering HSTS

  1. Request an HTTP home-page URL and confirm it redirects to HTTPS.
  2. Repeat with a deep article URL and a URL containing a query string.
  3. Confirm there is no redirect loop and the final page returns successfully.
  4. Test Administrator separately.

Only consider HTTP Strict Transport Security after HTTPS is stable for the entire hostname and you understand its persistence and subdomain implications. HSTS is not a substitute for a working server-side redirect.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket