# Nginx + certbot - redirect https www to https

**URL:** <https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678>\
**Category:** Help\
**Created:** [January 13, 2021, 4:40pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678 "2021-01-13T16:40:17Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![xBaSic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/xbasic/32/46169_2.png) [@xBaSic](https://community.letsencrypt.org/u/xBaSic)\
**Post date:** [January 13, 2021, 4:40pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/1 "2021-01-13T16:40:17Z")

</div>

Hello. I'm having a problem with the redirection of my domain.

I've sucessfully redirected http-www and http to https but nothing seems to work in case of https-www to https redirection. Below is my nginx config.

```
server {
        server_name domain.com www.domain.com;   

	location / {
        	proxy_pass http://localhost:3000;
        	#proxy_http_version 1.1;
        	#proxy_set_header Upgrade $http_upgrade;
        	#proxy_set_header Connection 'upgrade';
        	#proxy_set_header Host $host;
        	#proxy_cache_bypass $http_upgrade;
	}

    listen 443 ssl; # managed by Certbot
    ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem; # managed by Certbot
    include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
}

server {
    if ($host = www.domain.com) {
        return 301 https://domain.com$request_uri;
    } # managed by Certbot

    if ($host = domain.com) {
        return 301 https://$host$request_uri;
    } # managed by Certbot

    server_name domain.com www.domain.com;
    listen 80;
    return 404; # managed by Certbot
}

```

I've tried creating additional server blocks etc. but i can't make it working.

Thank you in advance!

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [January 13, 2021, 4:50pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/2 "2021-01-13T16:50:04Z")

</div>

Hello @xBaSic,

Just remove `www.domain.com` from the server block and create a new one and then redirect to `https://domain.com` from that server block.

Like this:

```
server {
    server_name www.domain.com;   
    return 301 https://domain.com$request_uri;
    listen 443 ssl; 
    ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
}
server {
        server_name domain.com;   

	location / {
        	proxy_pass http://localhost:3000;
        	#proxy_http_version 1.1;
        	#proxy_set_header Upgrade $http_upgrade;
        	#proxy_set_header Connection 'upgrade';
        	#proxy_set_header Host $host;
        	#proxy_cache_bypass $http_upgrade;
	}

    listen 443 ssl; # managed by Certbot
    ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem; # managed by Certbot
    include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
}

server {
    if ($host = www.domain.com) {
        return 301 https://domain.com$request_uri;
    } # managed by Certbot

    if ($host = domain.com) {
        return 301 https://$host$request_uri;
    } # managed by Certbot

    server_name domain.com www.domain.com;
    listen 80;
    return 404; # managed by Certbot
} 

```

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![xBaSic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/xbasic/32/46169_2.png) [@xBaSic](https://community.letsencrypt.org/u/xBaSic)\
**Post date:** [January 14, 2021, 5:55pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/3 "2021-01-14T17:55:36Z")

</div>

Hey I implemented the changes and now addres [http://www.example.com/](http://www.example.com/) is not working.

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [January 14, 2021, 11:44pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/4 "2021-01-14T23:44:53Z")

</div>

What means "is not working"?

Could you please share your real domain so we can test it?

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![xBaSic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/xbasic/32/46169_2.png) [@xBaSic](https://community.letsencrypt.org/u/xBaSic)\
**Post date:** [January 15, 2021, 12:00am UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/5 "2021-01-15T00:00:58Z")

</div>

Sure it's prawnyregulamin.pl

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [January 15, 2021, 12:35am UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/6 "2021-01-15T00:35:10Z")

</div>

I've tested exactly the same conf I pasted above in my server and it is working fine so seems there is another conf file in your nginx serving your domain.

Please, show the output of this command:

`grep -ri prawnyregulamin.pl /etc/nginx/*`

---

<div class="post-metadata">

**Author:** ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)\
**Post date:** [January 15, 2021, 2:35am UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/7 "2021-01-15T02:35:14Z")

</div>

> [@xBaSic](#):
>
> prawnyregulamin.pl

Looks great from here!

---

<div class="post-metadata">

**Author:** ![Litbelb](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/litbelb/32/46707_2.png) [@Litbelb](https://community.letsencrypt.org/u/Litbelb)\
**Post date:** [January 15, 2021, 2:48am UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/8 "2021-01-15T02:48:15Z")

</div>

I’ve got a 404 unless I access it via https - but I can access it fine. Is there a load balancer in place here?

---

<div class="post-metadata">

**Author:** ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)\
**Post date:** [January 15, 2021, 3:00am UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/9 "2021-01-15T03:00:40Z")

</div>

```
curl -Iki prawnyregulamin.pl

```

HTTP/1.1 404 Not Found  
Server: nginx/1.18.0 (Ubuntu)  
Date: Fri, 15 Jan 2021 02:56:37 GMT  
Content-Type: text/html  
Content-Length: 162  
Connection: keep-alive  
Vary: Accept-Encoding

So I am getting a 404 with curl without a protocol declaration....

rip:T430 ~ \>\> curl -Iki [https://prawnyregulamin.pl](https://prawnyregulamin.pl)  
HTTP/1.1 200 OK  
Server: nginx/1.18.0 (Ubuntu)  
Date: Fri, 15 Jan 2021 02:57:15 GMT  
Content-Type: text/html  
Connection: keep-alive  
Vary: Accept-Encoding

But the https is returning the correct response.  
Hope this helps  
Works ok in firefox from my location though.  
@sahsanu... does this help?

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [January 15, 2021, 10:38am UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/10 "2021-01-15T10:38:13Z")

</div>

@Rip, yes, the http part is the problematic one, https is working fine. It is like nginx is ignoring the ifs in this server block:

```
server {
    if ($host = www.domain.com) {
        return 301 https://domain.com$request_uri;
    } # managed by Certbot

    if ($host = domain.com) {
        return 301 https://$host$request_uri;
    } # managed by Certbot

    server_name domain.com www.domain.com;
    listen 80;
    return 404; # managed by Certbot
} 

```

but I tested this conf in my server and all is working fine, redirections are being done, so or there is a typo in the server block or there is another server block taking precedence.

@xBaSic, to know whether nginx is using that server block you can replace:

`return 404; # managed by Certbot`

by

`return 405; # managed by Certbot`

and reload nginx `systemctl reload nginx` so if we get a 405 error instead of 404 we will know that nginx is using the server block and ifs are not working.

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![xBaSic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/xbasic/32/46169_2.png) [@xBaSic](https://community.letsencrypt.org/u/xBaSic)\
**Post date:** [January 15, 2021, 2:20pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/11 "2021-01-15T14:20:55Z")

</div>

Ok, i've changed from 404 to 405.

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [January 15, 2021, 2:26pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/12 "2021-01-15T14:26:02Z")

</div>

@xBaSic, ok, I get the 405 code so for whatever reason I don't know nginx is ignoring the if part, so to do it easy just change this:

```
server {
    if ($host = www.domain.com) {
        return 301 https://domain.com$request_uri;
    } # managed by Certbot

    if ($host = domain.com) {
        return 301 https://$host$request_uri;
    } # managed by Certbot

    server_name domain.com www.domain.com;
    listen 80;
    return 405; # managed by Certbot
}

```

to this

```
server {
    server_name domain.com www.domain.com;
    listen 80;
    return 301 https://domain.com$request_uri;
}

```

Restart or reload nginx and we will try again.

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![xBaSic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/xbasic/32/46169_2.png) [@xBaSic](https://community.letsencrypt.org/u/xBaSic)\
**Post date:** [January 15, 2021, 2:37pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/13 "2021-01-15T14:37:57Z")

</div>

Ok, i've done the changes.

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [January 15, 2021, 2:41pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/14 "2021-01-15T14:41:43Z")

</div>

Perfect, from my side all is working fine now.

---

<div class="post-metadata">

**Author:** ![xBaSic](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/xbasic/32/46169_2.png) [@xBaSic](https://community.letsencrypt.org/u/xBaSic)\
**Post date:** [January 15, 2021, 2:42pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/15 "2021-01-15T14:42:41Z")

</div>

Yup. It looks like it's working fine now... Thank you very much... i've been trying to fix this for ages before i created this thread. I was trying all kind of redirections with no succeess.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [February 14, 2021, 2:42pm UTC](https://community.letsencrypt.org/t/nginx-certbot-redirect-https-www-to-https/142678/16 "2021-02-14T14:42:48Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
