# Let's Encrypt - switch to HTTPS

**URL:** <https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345>\
**Category:** RapidWeaver Classic\
**Created:** [April 15, 2016, 3:16am UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345 "2016-04-15T03:16:40Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![lynnnight](https://avatars.discourse-cdn.com/v4/letter/l/e274bd/32.png) [@lynnnight](https://forums.realmacsoftware.com/u/lynnnight)\
**Post date:** [April 15, 2016, 3:16am UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/1 "2016-04-15T03:16:40Z")

</div>

Anyone here have information about how one can make use of the free “Let’s Encrypt” to switch a RW site to HTTPS encryption?

Thanks!

> **[A Scheme to Encrypt the Entire Web Is Actually Working](https://www.wired.com/2016/04/scheme-encrypt-entire-web-actually-working/)**
>
> The non-profit certificate authority Let's Encrypt is enabling a sea change toward HTTPS encryption online.

---

<div class="post-metadata">

**Author:** ![scottsteven](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/scottsteven/32/3418_2.png) [@scottsteven](https://forums.realmacsoftware.com/u/scottsteven)\
**Post date:** [April 15, 2016, 3:47am UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/2 "2016-04-15T03:47:25Z")

</div>

yep here is how it works

> **[How It Works - Let's Encrypt - Free SSL/TLS Certificates](https://letsencrypt.org/how-it-works/)**
>
> The objective of Let’s Encrypt and the ACME protocol is to make it possible to set up an HTTPS server and have it automatically obtain a browser-trusted certificate, without any human intervention. This is accomplished by running a certificate...

Just like any other SSL you need access to the server to generate CSR etc. You either need to own your own servers or need to contact your hosting company.

As below link states this SSL is trusted be most browsers finally.

[https://helloworld.letsencrypt.org](https://helloworld.letsencrypt.org)

Now some browsers especially older ones will toss an error saying do you want to trust the site but if you click through and manually agree that this is a trusted site.

for a shopping cart I would probably spend the 25 bucks for a commercial SSL that normally have fraud insurance policy behind it say 5OK USD .

---

<div class="post-metadata">

**Author:** ![lynnnight](https://avatars.discourse-cdn.com/v4/letter/l/e274bd/32.png) [@lynnnight](https://forums.realmacsoftware.com/u/lynnnight)\
**Post date:** [April 15, 2016, 4:09am UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/3 "2016-04-15T04:09:15Z")

</div>

Thanks so much for the info @scottsteven! Very helpful!

---

<div class="post-metadata">

**Author:** ![Shadow](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/shadow/32/3390_2.png) [@Shadow](https://forums.realmacsoftware.com/u/Shadow)\
**Post date:** [April 15, 2016, 3:01pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/4 "2016-04-15T15:01:41Z")

</div>

I use [http://cloudflare.com](http://cloudflare.com). It has a lot of great features without having to pay for the premium plans.

---

<div class="post-metadata">

**Author:** ![garageshop](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/garageshop/32/366_2.png) [@garageshop](https://forums.realmacsoftware.com/u/garageshop)\
**Post date:** [April 15, 2016, 7:30pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/5 "2016-04-15T19:30:48Z")

</div>

I second Cloudflare. I use the free service on every site I build. Simple and effective.  
Blessings,  
—Mark

---

<div class="post-metadata">

**Author:** ![lynnnight](https://avatars.discourse-cdn.com/v4/letter/l/e274bd/32.png) [@lynnnight](https://forums.realmacsoftware.com/u/lynnnight)\
**Post date:** [April 15, 2016, 7:59pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/6 "2016-04-15T19:59:07Z")

</div>

Thanks for the tips about Cloudflare too!

---

<div class="post-metadata">

**Author:** ![barchard](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/barchard/32/2292_2.png) [@barchard](https://forums.realmacsoftware.com/u/barchard)\
**Post date:** [April 27, 2016, 11:31pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/7 "2016-04-27T23:31:51Z")

</div>

I haven’t made a formal announcement yet, but Let’s Encrypt is now available for all users directly from within the [Chillidog Hosting](https://www.chillidoghosting.com) control panel 🙂

 ![](https://europe1.discourse-cdn.com/flex005/uploads/realmacsoftware1/original/2X/3/39068010babe32399513a06d208b19d2d09bc911.png)

 ![](https://europe1.discourse-cdn.com/flex005/uploads/realmacsoftware1/original/2X/5/5e52c1bbd9c1b86178cb029d5a011581f64b7052.png)

-Greg

---

<div class="post-metadata">

**Author:** ![Shadow](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/shadow/32/3390_2.png) [@Shadow](https://forums.realmacsoftware.com/u/Shadow)\
**Post date:** [April 28, 2016, 2:40pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/8 "2016-04-28T14:40:22Z")

</div>

Nice work Greg! I This is a great service to offer.

---

<div class="post-metadata">

**Author:** ![robbeattie](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/robbeattie/32/78_2.png) [@robbeattie](https://forums.realmacsoftware.com/u/robbeattie)\
**Post date:** [April 28, 2016, 6:13pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/9 "2016-04-28T18:13:55Z")

</div>

That’s interesting Greg. Will there be any docs on how to use it and the benefits of doing so?

Rob

---

<div class="post-metadata">

**Author:** ![swilliam](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/swilliam/32/14799_2.png) [@swilliam](https://forums.realmacsoftware.com/u/swilliam)\
**Post date:** [April 28, 2016, 6:15pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/10 "2016-04-28T18:15:08Z")

</div>

Or the pitfalls…

And the rest of the 20 characters

---

<div class="post-metadata">

**Author:** ![barchard](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/barchard/32/2292_2.png) [@barchard](https://forums.realmacsoftware.com/u/barchard)\
**Post date:** [April 28, 2016, 6:24pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/11 "2016-04-28T18:24:35Z")

</div>

Not at the moment. Little wrapped up with a couple things. It should be pretty straight forward (I hope). Just click the domain you want and hit go. It handles the set up and renewals for you automatically.

Pros:  
Free  
Automatic

Cons:  
Not insured  
Potential exploit which would affect the trust of these certs:

> **[Let's Encrypt Now Being Abused By Malvertisers - TrendLabs Security Intelligence...](https://blog.trendmicro.com/trendlabs-security-intelligence/lets-encrypt-now-being-abused-by-malvertisers/)**
>
> Encrypting all HTTP traffic has long been considered a key security goal, but there have been two key obstacles to this. First, certificates are not free and many owners are unwilling to pay; secondly the certificates themselves are not always...

A note about cloudflare’s SSL option above. This only encrypts data between cloudflare and the end user. The data transferred from the host to cloudflare is unencrypted. You must have a SSL certificate set up for your website to ensure that you have end to end encryption (host to cloudflare and cloudflare to end user).

You could, in theory, use lets encrypt and cloudflare (both free versions) for full end to end encryption. This is great for the masses. If I’m running a business, however, I might buy a certificate from a trusted source. The issuer of my certificates has some integrity associated with it.

Greg

---

<div class="post-metadata">

**Author:** ![tj87](https://avatars.discourse-cdn.com/v4/letter/t/5f8ce5/32.png) [@tj87](https://forums.realmacsoftware.com/u/tj87)\
**Post date:** [December 15, 2016, 10:37pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/12 "2016-12-15T22:37:12Z")

</div>

Thanks for the tip, I used Cloudflare for my new site and it’s amazing…but only if I type in https:// if anyone just types in the website address or www. they get to the non-secure http:// version.

Is there a way I can fix that?

---

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [December 15, 2016, 10:57pm UTC](https://forums.realmacsoftware.com/t/lets-encrypt-switch-to-https/6345/13 "2016-12-15T22:57:40Z")

</div>

You can add a .htaccess file (or add entries to an existing .htaccess file to redirect your www and your http:/. to the https://. You can also use cloud flare to do this as well.
