6 ms·
Custom domains on GitHub Pages gain support for HTTPS
- vinhboy 8y agoMy site says "Unavailable for your site because your domain is not properly configured to support HTTPS", but I don't see instructions to resolve it?
- Spazer 8y agoIf your site is configured with A records, you’ll need to change the IPs it’s pointing to before you’ll be able to get a cert: 185.199.108.153 185.199.109.153 185.199.110.153 185.199.111.153 From: https://help.github.com/articles/setting-up-an-apex-domain/ https://help.github.com/articles/setting-up-an-apex-domain/ EDIT: You’ll also need to remove and re-add the domain in the repository settings after doing that too to trigger it to request a cert.
- myroon5 8y agoCan you expand on how to perform the steps added in your edit? Thanks!
- Spazer 8y agoGo to the GitHub pages section of the repo settings, delete your domain name from the custom domain input, hit save, then add it back and save again. If it’s still not working after that the you can contact support and they can press a button on the back end to trigger a cert request.
- toshimaru 8y agoThis worked for me! thanks!
- myroon5 8y agoDidn't work for me. Might have something to do with the fact that I also have a CNAME file in my repo. I'll reach out to support
- skluck 8y agoHow long have you waited? For a while (After updating to their new IPs and enabling/disabling custom domain) it said it was unavailable, but then after 60-90 minutes both of my repos are now in "Not yet available for your site because the certificate has not finished being issued" state. I guess I'll have a better idea tomorrow if it worked or not but for now I'm hoping this is just my repos working their way through github's cert queue. * I also have CNAME files in my projects.
- mitsudomoe8 8y agoCould you please update us once it's done? I have got exactly the same issue.
- sinistersnare 8y agoI use Cloudflare to get HTTPS on my github pages site, and I really like it. I get a lot of control over cached content and security, and statistics about site traffic. I am kind of happy that GitHub did not support HTTPS for custom domains, because then I would not have learned how to use Cloudflare.
- minimaxir 8y agoI use Cloudflare on my GitHub pages site, but never saw a HTTPS option. How do you enable that? (and now with GitHub providing certs, is it a better idea to use theirs?)
- aaomidi 8y agoCloudflare's dynamic https would add https on the USER->Cloudflare side of communications.
- bad_user 8y agoCloudflare's HTTPS certificate is shared, which means that your website will share it with other dubious websites. I'm looking at a website on which I have Cloudflare enabled and my certificate is being shared with about 24 other domains. For somebody that knows what HTTPS is about and what it protects against, that's not acceptable. We only accepted it because we find it as being a reasonable compromise given the alternative. So why isn't Cloudflare generating Lets Encrypt certificates, instead of these shared ones? Given their fast response in pursuing other endeavors, my guess is that they need incentives for people to move to their business plans. Therefore I'm glad that GitHub Pages can have HTTPS enabled for custom domains. It means I can now turn off CloudFlare. I'm so glad in fact that I started paying GitHub for a $7 account, even though I don't currently have a need for private repos.
- dannyw 8y agoWhat exactly is the problem? Amazon does the same as well, I believe. The private keys are never given to you, or other sites. It is all within Cloudflare’s edge.
- secure 8y agoThis is great! Now, if only GitHub would be available via IPv6, that would remove the need for CloudFlare — not that I would necessarily remove CloudFlare, but I would feel better if my setup wasn’t dependent on it.
- modernerd 8y agoCan you host multiple HTTPS sites at different domains from one GitHub account?
- Spazer 8y agoYou get a site per repository!
- nickcannariato 8y agoYep! This is absolutely possible.
- jscholes 8y agoCould this be related to Google's recent announcement of the .app TLD with mandatory HTTPS[0]? [0]: https://www.blog.google/topics/developers/introducing-app-more-secure-home-apps-web/ https://www.blog.google/topics/developers/introducing-app-mo...
- JepZ 8y agoVery unlikely. Github is working on this since months/years [1] and it is much more likely they had to wait for wildcard support by let's encrypt plus a few weeks testing. Googles announcement is much more along the lines of Progressive Web Apps (PWA) and Service Workers which require HTTPS [2]. [1]: https://github.com/isaacs/github/issues/156 https://github.com/isaacs/github/issues/156 [2]: https://developers.google.com/web/progressive-web-apps/checklist https://developers.google.com/web/progressive-web-apps/check...
- pards 8y agoToo little, too late. I moved my repo to GitLab pages after Google announced it would prioritise sites that support HTTPS in its search results.
- majewsky 8y agoYou're wildly underestimating how difficult it is to roll out such a change in a backwards-compatible way. It's not like Github did this today after neglecting the feature request for years; they've been on public record at least many months ago saying that they were working on it. Even if only 1% of users were unable to access a site after the switch to HTTPS, the amount of calls to Github support would be massive.
- tonyztan 8y ago> "It's not like Github did this today after neglecting the feature request for years" https://github.com/isaacs/github/issues/156 https://github.com/isaacs/github/issues/156
- myroon5 8y agoHTTPS does work for my site now, but I get this warning: Your connection is not secure / Your connection is not private Error code: SSL_ERROR_BAD_CERT_DOMAIN (Firefox) NET::ERR_CERT_COMMON_NAME_INVALID (Chrome) Trying adding the A records as described here: https://help.github.com/articles/setting-up-an-apex-domain/ https://help.github.com/articles/setting-up-an-apex-domain/ Will update if that works..
- city41 8y agoI get that warning if I go to https://mycustomdomain.com https://mycustomdomain.com but I don't if I go to https://www.mycustomdomain.com https://www.mycustomdomain.com
- fladd 8y agoIt is the same for my domain. Seems to be a bug.
- epberry 8y agoSame here. Redirect from http -> https works fine tho.
- Philipp__ 8y agoSame here.
- fladd 8y agoI contacted GitHub support about this already. I hope this gets resolved soon.
- fladd 8y agoIt turns out that the apex for me now works only by accident, because I temporarily changed my custom domain to the apex form. This certificate will not get renewed, however. Only the domain that is active gets a certificate. That means that with https enabled it is no longer pssible to have the apex and www form of a custom domain work simultaneously at a GitHub page! One needs to decide for one or the other. As a workaround it was suggested to me to create a CNAME record from www to apex at the domain hoster. This, however, will not work for those of us who want to have it the other way around, that is, the apex pointing to the www form of the domain. I was told that GitHub might consider other solutions in the future.
- Cyberdog 8y agoI've been doing HTTPS on hosted domains for years, and I don't really get how it works in this case. Is it that you don't use your own certificate, but GitHub automatically generates one with Let's Encrypt for you? If not, then how exactly do you give GitHub your cert? The instructions seem vague on this.
- sattoshi 8y agoYou check a checkbox and they generate a cert for your domain. Simple.
- lostmsu 8y agoHm, I get SSL_ERROR_NO_CYPHER_OVERLAP in Firefox on https://stack.blogs.losttech.software/ https://stack.blogs.losttech.software/ , that is served from https://github.com/losttech/stack-blog https://github.com/losttech/stack-blog via Cloudflare.
- MightySCollins 8y agoSuch a shame they quietly broke IPv6 support.