Turn on HTTPS properly
A padlock is step one. Redirects, mixed content and cookies are the rest.
My site runs <stack> on <host>. I need HTTPS set up properly. Walk me through it for this specific host: - Getting and renewing the certificate. Is it automatic here? What do I click or run? - Redirecting every http:// request to https://, once, without a loop. - Finding mixed content: anything still loading over http. - Marking cookies Secure so they're never sent unencrypted. - Whether to turn on HSTS now, and why I might want to wait a week. Tell me how to test each step, and what breaks if I get the redirect wrong.
Leave HSTS until everything works over HTTPS for a few days. It tells browsers to refuse plain HTTP for months, so a mistake made with it switched on is hard to undo.