Plesk

Securing Connections with the SSL It! Extension – Enhancing security of your websites and encrypted server connections

Merely securing a website
with a valid SSL/TLS certificate from a trusted CA
is not enough to get all-round protection.
SSL is a complex technology,
which has a number of features (key encryption algorithm, secure ciphers,
HSTS, and much more) that can do the following:

Enabling these features can improve your websites’ search engine rankings:

Caution: Before turning these features on,
ensure that your website can be accessed
via HTTPS without any issues.
Otherwise, visitors may have trouble accessing your website.

Note: If you have already set up HSTS or OCSP stapling
in your web server manually,
delete these customizations
before turning on HSTS or OCSP stapling in SSL It!.

To enhance the security of your websites and encrypted server connections:

  1. Secure your website with a valid SSL/TLS certificate from a trusted CA.

  2. Go to Websites & Domains > your domain > SSL/TLS Certificates.

  3. If you have upgraded to Plesk Obsidian from earlier Plesk versions,
    turn on “Redirect from http to https”.
    The redirect will be also applied for webmail by default.
    On clean Plesk Obsidian installations,
    the redirect for the domain and webmail is already turned on by default.

    Note: If your webmail is not secured with a valid SSL/TLS certificate
    or you do not have any webmail,
    clear the “Include webmail” checkbox.

  4. Enable HSTS:

    1. Turn on HSTS.

    2. Make sure that an SSL/TLS certificate
      that secures your website will be valid
      during the “Max-age” period.
      Do the same for subdomains and the webmail subdomain.
      Otherwise, if the SSL/TLS certificate expires earlier
      than the “Max-age” period and HSTS is turned on,
      visitors will not be able to access your website.