Get a free website with any plan

See how
APPLICATIONS

OpenCart SSL

Last updated

IN SHORT

Flashcloud auto-issues a free Let's Encrypt SSL certificate within five minutes of DNS pointing to your account. To secure OpenCart, set Use SSL to Yes under System > Settings in the admin and update your store URLs to HTTPS. The certificate alone does not secure your store until OpenCart's configuration matches.

Flashcloud auto-issues a free Let's Encrypt SSL certificate for every domain, usually within about 5 minutes of DNS pointing to us, and it renews automatically after that. For OpenCart, the certificate alone isn't enough: you also need to tell OpenCart to use HTTPS URLs everywhere. In the OpenCart admin, go to System > Settings, edit your store, open the Server tab, and set Use SSL to Yes. Miss that step and you'll see mixed-content warnings or a padlock that doesn't match the address bar.

If you installed OpenCart through Softaculous in cPanel, the certificate and the store config need to line up, or checkout pages and admin login will keep loading insecure assets.

Confirm the certificate is issued

Open cPanel from your service in accessing cPanel, and go to SSL/TLS Certificates. Your domain should show a valid Let's Encrypt certificate. If it's missing, DNS may not be pointing at Flashcloud yet on most hosting accounts; once DNS is correct, open a ticket if the certificate still hasn't appeared.

Turn on HTTPS inside OpenCart

Certificate issuance is automatic, but OpenCart doesn't know to use it until you tell it to. In the OpenCart admin, go to System > Settings, edit your store, and open the Server tab. Set:

  • Use SSL to Yes
  • HTTPS Server to https://yourdomain.com/ (matching your actual domain, trailing slash included)

Save. Older OpenCart versions may label these fields slightly differently, but the same Server tab settings apply.

Fix the config files if the admin panel won't save

Sometimes a permissions issue or a locked config file stops the settings page from saving. OpenCart keeps two config files at the root and in /admin/. Edit both directly through cPanel's File Manager, or an FTP client using credentials from cPanel's FTP Accounts tool, and confirm both HTTP_SERVER and HTTPS_SERVER constants use https://:

define('HTTP_SERVER', 'https://yourdomain.com/');
define('HTTPS_SERVER', 'https://yourdomain.com/');

// admin/config.php
define('HTTP_SERVER', 'https://yourdomain.com/admin/');
define('HTTPS_SERVER', 'https://yourdomain.com/admin/');

Save both files and reload the storefront. If the admin config file is set to read-only, right-click it in File Manager and adjust permissions before editing.

Clear mixed content and redirect HTTP to HTTPS

With Use SSL on, OpenCart forces its own pages to HTTPS, but two things commonly still leak insecure content:

  • Theme assets or extensions with hardcoded http:// URLs. Check your browser's console for mixed-content warnings after switching, and update any theme settings or custom modules that reference the old scheme directly.
  • Old links from search engines or bookmarks hitting the HTTP version. Add a redirect so HTTP traffic lands on HTTPS automatically, rather than relying on OpenCart's internal setting alone.

Run through LiteSpeed and Cloudflare, not around them

Flashcloud runs LiteSpeed with LSCache in front of every site, and Cloudflare at the edge with an optional proxy toggle on the portal's Cloudflare CDN page. Both play fine with HTTPS by default, but two settings are worth checking if you switched OpenCart to SSL and something looks off:

  • If the Cloudflare proxy is on for your domain, set SSL/TLS mode to Full or Full (strict), not Flexible. Flexible terminates SSL at Cloudflare's edge but talks HTTP to your origin, which can produce redirect loops once OpenCart itself is forcing HTTPS.
  • If pages still look stale after saving your SSL settings, purge cache from the Cloudflare CDN page. See how we make your site fast for how the caching layers fit together.

When to open a ticket

If the certificate never issues despite DNS being correct, if certificate issues persist after switching Use SSL to Yes, or if the change breaks checkout or admin login entirely, that's worth escalating. Open a ticket from Support in the portal. It goes to a real person, and if credentials or config file contents need to be shared, use the secure-share panel on the ticket rather than pasting them in plain text.

Common questions

Why is my store showing mixed-content warnings after turning on SSL?

Your theme or extensions still contain hardcoded HTTP links. Check your browser console to find the insecure assets, then update those theme or module settings to HTTPS.

Why am I stuck in a redirect loop after enabling SSL?

Your Cloudflare SSL/TLS mode is set to Flexible. Change the mode to Full or Full (strict) in Cloudflare so the proxy does not send HTTP requests to an origin that requires HTTPS.

What should I do if the OpenCart admin panel will not save my SSL settings?

Update the root and admin config.php files directly using cPanel File Manager or FTP. Set both HTTP_SERVER and HTTPS_SERVER constants to use HTTPS, and check file permissions if either file is read-only.

Why is my Let's Encrypt certificate missing in cPanel?

Your domain DNS may not point to Flashcloud yet. Let's Encrypt certificates generate automatically within about five minutes after DNS points to us.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.