How to fix ssl not accessible on OpenCart

Enable HTTPS on your store by opening port 443 and installing a valid SSL/TLS certificate so every page is served over a secure connection.

Steps for OpenCart

  1. Ensure port 443 is open on your server and a valid SSL certificate is installed.
  2. Edit your OpenCart config.php and admin/config.php files: change the HTTP_SERVER and HTTPS_SERVER constants to use https://.
  3. In Admin → Settings → Your Store → Server tab, enable 'Use SSL' and set the SSL URL to your https:// address.
  4. Optionally add an HTTP→HTTPS redirect in your .htaccess file.
Official OpenCart documentation ↗
## Nginx — minimal HTTPS server block with HTTP redirect

server {
    listen 80;
    server_name yourdomain.com www.yourdomain.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl http2;
    server_name yourdomain.com www.yourdomain.com;

    ssl_certificate     /etc/letsencrypt/live/yourdomain.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/yourdomain.com/privkey.pem;

    ssl_protocols       TLSv1.2 TLSv1.3;
    ssl_ciphers         HIGH:!aNULL:!MD5;

    # ... rest of your config
}

What is ssl not accessible?

Every website that uses HTTPS — the padlock in the browser address bar — communicates over TCP port 443. When port 443 is closed or unreachable, your store cannot serve any encrypted traffic at all: visitors get browser security warnings, payment flows break, and search engines may refuse to index your pages. An SSL/TLS certificate is the digital credential that makes this encrypted connection possible, and port 443 is the network "door" it must be delivered through. If that door is shut, HTTPS simply does not work, regardless of whether you have a certificate installed.

Google has used HTTPS as a ranking signal since 2014, and a store that is unreachable over HTTPS will be demoted or deindexed entirely — costing you organic traffic and revenue. Modern browsers (Chrome, Firefox, Safari, Edge) display a full-page "Not Secure" or "Connection Refused" warning when port 443 is blocked, causing shoppers to abandon immediately and destroying conversion rates. Payment card industry rules (PCI-DSS) require all cardholder data to be transmitted over encrypted channels; without HTTPS you are non-compliant and risk losing the ability to accept card payments. Under privacy regulations (GDPR, CCPA), transmitting customer data unencrypted is a reportable data breach waiting to happen.

See the complete Ssl not accessible guide for every platform and the full background.

Not sure if your OpenCart store has this?

Run a free SEOLZ audit — we’ll find ssl not accessible and every other issue across your whole site.

Scan my site free

Fix ssl not accessible on another platform