# Website connection insecure on mobile unless you manually prefix with https

**URL:** <https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638>\
**Category:** Help\
**Created:** [August 10, 2022, 10:04pm UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638 "2022-08-10T22:04:59Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 10, 2022, 10:04pm UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/1 "2022-08-10T22:04:59Z")

</div>

On desktop, when I go to [benrothman.org](http://benrothman.org) or [https://benrothman.org](https://benrothman.org) the site loads, on mobile when I go to [https://benrothman.org](https://benrothman.org) the site loads correctly. On mobile, if I go to [benrothman.org](http://benrothman.org) (without manually typing https://) the browser shows me a warning page saying that the connection to my website is not secure, Does anyone know the reason for this?

My domain is:  
[benrothman.org](http://benrothman.org)

I ran this command:  
certbot renew

The operating system my web server runs on is (include version):  
Ubuntu 20.04.03

I can login to a root shell on my machine (yes or no, or I don't know):  
yes

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [August 10, 2022, 10:11pm UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/2 "2022-08-10T22:11:53Z")

</div>

Probably because you redirect them to an IP address and not your domain name. The client then makes a request to the IP and the cert only has the domain name in it so is a mis-match. My test http request:

```nohighlight
curl -I http://benrothman.org

HTTP/1.1 301 Moved Permanently
Server: Apache/2.4.41 (Ubuntu)
Location: https://192.241.135.115/

```

The Location should be: `https://benrothman.org`/

---

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 10, 2022, 10:21pm UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/3 "2022-08-10T22:21:36Z")

</div>

@MikeMcQ  
so just to see if I am understanding what you are saying, you think the issue is an incorrect DNS record or an incorrect WordPress database value?

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [August 10, 2022, 10:24pm UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/4 "2022-08-10T22:24:26Z")

</div>

No. Your server is redirecting HTTP requests to the wrong name.

Did you configure your Apache server yourself?

---

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 10, 2022, 10:30pm UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/5 "2022-08-10T22:30:47Z")

</div>

@MikeMcQ some of it. Why, where is the incorrect redirect? it is not in the database

---

<div class="post-metadata">

**Author:** ![jvanasco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jvanasco/32/55900_2.png) [@jvanasco](https://community.letsencrypt.org/u/jvanasco)\
**Post date:** [August 10, 2022, 10:52pm UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/6 "2022-08-10T22:52:36Z")

</div>

it's probably in the .htaccess file on the root directory.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [August 10, 2022, 11:16pm UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/7 "2022-08-10T23:16:54Z")

</div>

Can you show the output of this command:

```nohighlight
apachectl -t -D DUMP_VHOSTS

```

---

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 10, 2022, 11:48pm UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/8 "2022-08-10T23:48:19Z")

</div>

@jvanasco as in add something to htaccess?

---

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 11, 2022, 12:15am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/9 "2022-08-11T00:15:49Z")

</div>

@MikeMcQ

```nohighlight
# apachectl -t -D DUMP_VHOSTS
VirtualHost configuration:
*:443 192.241.135.115 (/etc/apache2/sites-enabled/000-default-le-ssl.conf:2)
*:80 192.241.135.115 (/etc/apache2/sites-enabled/000-default.conf:4)

```

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [August 11, 2022, 12:21am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/10 "2022-08-11T00:21:12Z")

</div>

> [@bennyandthejets82](#):
>
> `/etc/apache2/sites-enabled/000-default.conf`

Can you show the contents of this file? Please put 3 _backticks_ before and after the output like this:  
```  
contents of file  
```

---

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 11, 2022, 12:25am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/11 "2022-08-11T00:25:04Z")

</div>

@MikeMcQ

```nohighlight
# Added to mitigate CVE-2017-8295 vulnerability
UseCanonicalName On

<VirtualHost *:80>
        ServerAdmin webmaster@localhost
        
        ServerName 192.241.135.115
        ServerAlias www.192.241.135.115
        
        DocumentRoot /var/www/html

        <Directory /var/www/html/>
            Options FollowSymLinks
            AllowOverride All
            Require all granted
        </Directory>

        ErrorLog ${APACHE_LOG_DIR}/error.log
        CustomLog ${APACHE_LOG_DIR}/access.log combined
RewriteEngine on
RewriteCond %{SERVER_NAME} =benrothman.org [OR]
RewriteCond %{SERVER_NAME} =www.192.241.135.115 [OR]
RewriteCond %{SERVER_NAME} =192.241.135.115
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>

```

can you see the issue?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 11, 2022, 1:48am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/12 "2022-08-11T01:48:26Z")

</div>

> [@bennyandthejets82](#):
>
> can you see the issue?

Yes:

> [@bennyandthejets82](#):
>
> `RewriteRule ^ https://%{SERVER_NAME}`

where

> [@bennyandthejets82](#):
>
> `ServerName 192.241.135.115`

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 11, 2022, 1:50am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/13 "2022-08-11T01:50:48Z")

</div>

This is NOT a valid FQDN.  
[not one that can be resolved via global DNS]

> [@bennyandthejets82](#):
>
> `ServerAlias www.192.241.135.115`

---

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 11, 2022, 1:56am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/14 "2022-08-11T01:56:26Z")

</div>

@rg305

Thank you, but I am unclear on how to fix this,

1. Delete the line: `RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]`
2. Change this line `ServerAlias www.192.241.135.115` to what?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 11, 2022, 2:03am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/16 "2022-08-11T02:03:39Z")

</div>

I'd replace all occurrences of "`192.241.135.115`" with "`benrothman.org`".  
Then remove the unnecessary duplicate `RewriteCond` line:

> [@bennyandthejets82](#):
>
> ```nohighlight
> RewriteCond %{SERVER_NAME} =benrothman.org [OR] <<<<<<<<<<<<<<<<<<<< remove
> RewriteCond %{SERVER_NAME} =www.benrothman.org [OR]
> RewriteCond %{SERVER_NAME} =benrothman.org
> 
> ```

---

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 11, 2022, 2:33am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/17 "2022-08-11T02:33:31Z")

</div>

@rg305 yes thank you, that fixed it!

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [August 11, 2022, 2:40am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/18 "2022-08-11T02:40:58Z")

</div>

> [@bennyandthejets82](#):
>
> `/etc/apache2/sites-enabled/000-default-le-ssl.conf`

You probably should make similar changes of the domain name in your SSL config as Rudy described for your HTTP VirtualHost.

If you show the contents of this ssl.conf file we can describe the best options.

---

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 11, 2022, 3:02am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/19 "2022-08-11T03:02:37Z")

</div>

@MikeMcQ Why is it good to change the ssl conf? What will those changes do?

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [August 11, 2022, 3:07am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/20 "2022-08-11T03:07:16Z")

</div>

Probably nothing now. But, just remember if you ever add another domain name to your server it probably won't work. You are relying on Apache's default server name selection and not using SNI as intended (probably, won't know for sure until we see ssl conf).

---

<div class="post-metadata">

**Author:** ![bennyandthejets82](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bennyandthejets82/32/29133_2.png) [@bennyandthejets82](https://community.letsencrypt.org/u/bennyandthejets82)\
**Post date:** [August 11, 2022, 3:09am UTC](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638/21 "2022-08-11T03:09:10Z")

</div>

@MikeMcQ

```nohighlight
<IfModule mod_ssl.c>
<VirtualHost *:443>
        ServerAdmin webmaster@localhost
        
        ServerName 192.241.135.115
        ServerAlias www.192.241.135.115
        
        DocumentRoot /var/www/html

        <Directory /var/www/html/>
            Options FollowSymLinks
            AllowOverride All
            Require all granted
        </Directory>

        ErrorLog ${APACHE_LOG_DIR}/error.log
        CustomLog ${APACHE_LOG_DIR}/access.log combined

ServerAlias benrothman.org
Include /etc/letsencrypt/options-ssl-apache.conf
ServerAlias www.benrothman.org
SSLCertificateFile /etc/letsencrypt/live/benrothman.org/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/benrothman.org/privkey.pem
</VirtualHost>
</IfModule>

```

[Next page](https://community.letsencrypt.org/t/website-connection-insecure-on-mobile-unless-you-manually-prefix-with-https/182638.md?page=2)
