Cyber Security

SSL Configuration

A padlock in the address bar is only the start. We configure HTTPS properly, verify it from outside, and make sure certificates renew without anyone having to remember.

What SSL configuration involves

SSL — more accurately TLS today — encrypts the connection between your visitors and your server, so passwords, form submissions and payment details cannot be read or altered in transit. Getting a certificate is easy; configuring it well is where many sites fall short. An incomplete certificate chain can break the site on some devices, outdated protocol versions weaken the encryption, and a single image loaded over plain HTTP can trigger browser warnings.

Our SSL configuration service covers the certificate, the server settings around it and the site content that depends on it, so HTTPS works correctly for every visitor and keeps working after renewal.

It also matters beyond the browser. Payment gateways, mobile apps and partner systems that call your API usually refuse to connect to an endpoint with an invalid or incomplete certificate, and they often fail without a friendly error message. A webhook from your payment provider that silently stops arriving is a common, and expensive, symptom of a certificate problem that nobody noticed. Email servers, admin panels and internal tools deserve the same care as the public website, because they carry passwords and customer data too.

Who needs it, and the warning signs

Every website should serve HTTPS. This service is particularly useful when you run several domains and subdomains, operate your own server rather than managed hosting, or have recently moved hosts. A clinic’s booking site, a real estate portal with many subdomains, or a store about to go live with a payment gateway are typical cases.

  • Browsers show a not-secure or mixed-content warning on some pages.
  • The site works on desktop but shows certificate errors on some phones.
  • A certificate expired unexpectedly and the site went down.
  • Old protocol versions such as TLS 1.0 or 1.1 are still enabled.
  • Nobody knows where certificates come from or when they expire.

What’s included

  • Certificates issued and installed — typically free, automated certificates from Let’s Encrypt, or a commercial certificate you already hold.
  • Complete certificate chains, so every client can validate the certificate.
  • Modern protocols — TLS 1.2 and TLS 1.3 — with strong cipher suites and older versions disabled.
  • Redirects from HTTP to HTTPS and a single canonical hostname.
  • HSTS where appropriate, after confirming every subdomain is ready for it.
  • Mixed content removed, by updating hard-coded HTTP links to images, scripts and fonts.
  • Automated renewal with monitoring, so an expiry alert arrives well before a certificate lapses.

How we deliver it

  1. Inventory every domain and subdomain, where it is hosted and whether it sits behind a CDN or proxy such as Cloudflare.
  2. Test externally to record the current grade, protocol support and chain issues.
  3. Configure the web server (nginx, Apache or a reverse proxy) and the CDN settings so they agree with each other.
  4. Fix content that loads insecure resources.
  5. Re-test from outside to confirm the result rather than trusting the config file.
  6. Set up renewal and alerts, then document where each certificate lives and how it renews.

A note on HSTS

HTTP Strict Transport Security tells browsers to use HTTPS only for your domain. It is valuable, but it is also sticky: once a browser has seen the header, it will refuse plain HTTP for the time you specified. If a subdomain is not ready for HTTPS, it becomes unreachable for those visitors. That is why we enable HSTS gradually, starting with a short duration, and only include subdomains once they have all been checked.

Strong TLS protects data in transit. It does not protect a vulnerable application, so treat it as one layer of website security, not a replacement for it.

What affects timeline and cost

  • The number of domains, subdomains and servers involved.
  • Whether a CDN, load balancer or reverse proxy terminates TLS in front of your server.
  • How much hard-coded HTTP content needs updating in the site or database.
  • Access to DNS, which some certificate validation methods require.

Common mistakes

  • Installing only the site certificate and not the intermediate certificate, so some devices reject it.
  • A CDN set to flexible mode, which encrypts the visitor’s connection but sends traffic to the server unencrypted.
  • Automatic renewal configured but failing silently for months.
  • Enabling long-lived HSTS with subdomains before checking every subdomain works over HTTPS.

Frequently asked questions

Do we need to buy a paid certificate?

For most websites, free automated certificates from Let’s Encrypt provide the same encryption. A paid certificate can make sense for specific organisational or contractual requirements, and we can install one if you have it.

Will switching to HTTPS affect our search rankings?

Done properly, with permanent redirects and consistent URLs, the move to HTTPS should not harm rankings. We make sure redirects and canonical addresses are set up correctly.

We use Cloudflare. Is that enough?

Cloudflare can handle the visitor-facing certificate, but the connection from Cloudflare to your server also needs to be encrypted and validated. We configure both ends so they match.

Does TLS slow the website down?

On modern servers the overhead is small, and TLS 1.3 needs fewer round trips to set up a connection than older versions. HTTPS is also required for newer, faster protocols such as HTTP/2 in browsers.

How do we know renewal is working?

We set up monitoring that checks the certificate’s expiry date from outside and alerts well in advance, so a failed renewal is noticed long before visitors see an error.

Talk to us about ssl configuration

Strong ciphers, correct certificate chains and no mixed-content warnings.

Let's talk

Have something you need built, hosted or fixed?

Tell us what you are trying to do. If we are not the right people for it, we will say so.