- Why use HTTPS
- Enabling HTTPS
- Frequently Asked Questions
- Manage in Internet Explorer
- Manage in Chrome
- Manage in Firefox
Why use HTTPS
If you sign in to WordPress.com via a non-secure Internet connection, like a public Wi-Fi connection at your local coffee shop, your account may be more vulnerable to hijacking. To keep the bad guys out, we recommend using HTTPS.
To enable HTTPS you need to head on over to the Users –> Personal Settings screen.
Once there you want to check the box that says “Always use HTTPS when visiting administration pages” and then press the Save Changes button at the bottom of the page. When you log back in, you’ll be rolling with SSL encryption.
Frequently Asked Questions
Does it slow down WordPress.com ?
With this option turned on, you may find that WordPress.com is more sluggish over the https connection. That’s because nothing that’s transmitted over SSL is cached, so it takes some extra work to re-download all the information on a page.
How do I get those annoying security warnings to go away?
You may receive warnings as you navigate around your admin with HTTPS enabled.
These warnings are actually quite normal. When you see the alert on your WordPress.com dashboard, it’s usually a misguided warning more than anything, and you will only see it when logged in.
When you connect to your Dashboard over an HTTPS connection, we use an SSL certificate to encrypt your connection. SSL certificates need to be signed to a specific domain, and we can’t provide certificates for every mapped domain, so our certificate is signed for WordPress.com.
When you connect to your Dashboard via your own domain but your security software sees a certificate signed to http://wordpress.com/ it’s alerting you that WordPress.com may be intercepting your connection, which of course is perfectly fine. You may also see this warning if you attempt to reach your blog (not your Dashboard) using “https” instead of “http” in your blog URL.
Most security systems should have a way to add a permanent exception so you will never see the warning again in this instance.
Manage in Internet Explorer
- Go to Tools > Internet Options in your browser menu.
- Add *.wordpress.com to your list of trusted sites under the Security tab. Make sure to uncheck the box for “Require server verification (https:) for all sites in this zone.”
- Set Internet Options> Security> Trusted Sites> Custom Level> Miscellaneous> Display Mixed Content to “Enable” (you’ll have to do lots of scrolling to get there).
- Click OK on all windows.
Manage in Chrome
- Click on the padlock icon in the address bar
- Click on “Certificate Information”
- There should be a blue-framed “Certificate” icon – click and drag that image to your desktop.
- Double-click on the certificate file (*.wordpress.cer)
- Keychain will then ask you if you want to add this certificate
- Go to Keychain
- Choose “login” under Keychains and “Certificates” under Category
- Double click on the correct Certificate
- Twirl open the “Trust” area
- Select “Always Trust” in the When Using This Certificate dropdown.
- You will be prompted for your computer password to make changes to your Keychain.
- The red X will turn to a blue +
- Restart Chrome.
Manage in Firefox
- Go to Firefox menu > Preferences > Advanced > Certificates
- Choose your preference