{"id":18907616,"url":"https://github.com/tomodomoco/ssl-subdomain-for-multisite","last_synced_at":"2025-10-04T14:51:22.927Z","repository":{"id":2485901,"uuid":"3459532","full_name":"TomodomoCo/ssl-subdomain-for-multisite","owner":"TomodomoCo","description":"Ensures logins are always done via SSL on a subdomain of the master domain, but that access to custom domains are always done over HTTP, to avoid certificate errors. For WordPress Multisite.","archived":false,"fork":false,"pushed_at":"2012-03-28T08:28:18.000Z","size":96,"stargazers_count":2,"open_issues_count":0,"forks_count":0,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-06-01T00:52:01.888Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/TomodomoCo.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2012-02-16T12:04:35.000Z","updated_at":"2013-11-26T13:38:57.000Z","dependencies_parsed_at":"2022-08-25T16:01:51.160Z","dependency_job_id":null,"html_url":"https://github.com/TomodomoCo/ssl-subdomain-for-multisite","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/TomodomoCo/ssl-subdomain-for-multisite","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TomodomoCo%2Fssl-subdomain-for-multisite","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TomodomoCo%2Fssl-subdomain-for-multisite/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TomodomoCo%2Fssl-subdomain-for-multisite/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TomodomoCo%2Fssl-subdomain-for-multisite/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/TomodomoCo","download_url":"https://codeload.github.com/TomodomoCo/ssl-subdomain-for-multisite/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TomodomoCo%2Fssl-subdomain-for-multisite/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":261505205,"owners_count":23168981,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-08T09:22:31.687Z","updated_at":"2025-10-04T14:51:17.890Z","avatar_url":"https://github.com/TomodomoCo.png","language":"PHP","funding_links":[],"categories":[],"sub_categories":[],"readme":"SSL Subdomain for Multisite\n===========================\n\nEnsures logins are always done via SSL on a subdomain of the master domain, but that access to custom domains are always done over HTTP, to avoid certificate errors. For WordPress Multisite.\n\nWordPress’ built-in `FORCE_SSL_LOGIN` and `FORCE_SSL_ADMIN` directives in `wp-config.php` work great, but are too restrictive in situations where you have custom domains — custom domains for which you cannot have SSL certificates. For sites on custom domains, we need to make sure that the login and admin access happens over the subdomain, which can be properly served over HTTPS.\n\nWhat this Plugin does (incorporating Foolish Assumptions)\n---------------------------------------------------------\n\n \u003e *or, a readme you **should** read before implementing this plugin on your site.*\n \nThis plugin filters the login, logout, home and admin URLs that WordPress uses to generate its internal links.\n\nWhy do we do this?\n\n### The Scenario\n\nWe have a WordPress Multisite network. Let's call it `mynetwork.com`. We bought a fancy SSL wildcard certificate so we can offer `*.mynetwork.com` over a secure connection.\n\nWe’d very much like to use this secure connection for all logins, and for all admin access.\n\nWe also allow sites on this network to use a custom domain — like `demo-site.com`. We might be using [WPMU Domain Mapping](https://wordpress.org/extend/plugins/wordpress-mu-domain-mapping/) to achieve this. These sites have two domains, then — `demo-site.com` and `demo-site.mynetwork.com`.\n\nIf we switch on `FORCE_SSL_LOGIN` or `FORCE_SSL_ADMIN`, we have a problem. When users go to `https://demo-site.com/wp-login.php`, they get a certificate error. We have a wildcard certificate for `*.mynetwork.com`, but we can’t possibly have a valid SSL certificate installed for every custom domain!\n\nInstead, we want to force all login pages and admin pages to be:\n\n`https://demo-site.mynetwork.com/wp-admin/`…\n\nWe want all regular access to be:\n\n`http://demo-site.com/`…\n\nThis plugin facilitates that — rewriting the `wp-login` (including logout) and `wp-admin` URLs to the first example, and rewriting all the others to the second style.\n\n### Foolish Assumptions\n\nThis plugin makes some (foolish) assumptions about your multisite network. You must make sure that these assumptions are true for your site, or you will find that this plugin may have unintended consequences and break things that are difficult to fix without manually disabling the plugin.\n\n1.\tYour subdomains are in the format: `a.b`\n\t\t\u003e where `a` is, for example: `demo-site`.\n\t\t\u003e `b` is, for example: `mynetwork.com`.\n\t\t\u003e `a` **must** be a single domain component. (`a` can't be, for example: `demo.site`)\n\t\n\t\t\t\n2.\tYour wildcard certificate is configured properly for:\n\t\t\n\t*\t`*.mynetwork.com`\n\t*\tyour network site URL\n\t\n\tSo if your network site URL is `www.mynetwork.com`, your wildcard cert will be fine. If it is just `mynetwork.com`, you will need another cert to avoid errors when you go to `https://mynetwork.com/wp-admin`.)\n\t\t\t\t\n3.\tYour site already has the custom domains working.\n\t\t\n\t*\tI suggest the excellent [WPMU Domain Mapping](https://wordpress.org/extend/plugins/wordpress-mu-domain-mapping/) for this.\n\t\t\n\t\t*\tYour web server also needs to be [set up](http://www.lampjunkie.com/2008/05/how-to-set-up-a-wildcard-catch-all-virtual-host-in-apache/ \"A tutorial on wildcard catch all hosting for Apache\") to handle hosting a wildcard name virtual host. All of this is really part of the WPMU Domain Mapping set up, and not the set up for this plugin. I’m just, you know, mentioning it.\n\t\t\t  \n4.\tYou have the `FORCE_SSL_LOGIN` setting in `wp-config.php` **true**.\n\t\t\n5.\tYou have the `FORCE_SSL_ADMIN` setting in `wp-config.php` **false**. We’ll handle that — WordPress’ forcing of SSL admins will conflict with this plugin.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftomodomoco%2Fssl-subdomain-for-multisite","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftomodomoco%2Fssl-subdomain-for-multisite","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftomodomoco%2Fssl-subdomain-for-multisite/lists"}