Installing on Plesk

Securing Data Transmissions with HTTPS in ASP.NET: A Plesk Panel Guide

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (8 sections)

A padlock in the address bar protects only one connection: the visitor's browser talking to your site. An ASP.NET app sends data along several other routes too: to its database, to the mail server, to payment gateways and other APIs, and from your computer when you deploy. This guide goes through each connection on Domain India Windows hosting and shows how to keep the data on it encrypted.

Key takeaways

Serve the site over HTTPS with the free Let's Encrypt certificate in Plesk and one HTTP-to-HTTPS redirect, then add HSTS and Secure cookies. Keep the database connection encrypted (TrustServerCertificate=True skips only the certificate check). Send mail on port 465 with SSL/TLS, call APIs only over https:// without disabling certificate checks, and deploy with FTP using explicit TLS. Never switch off TLS validation to make an error go away.

Setting up the certificate itself

Installing the certificate and the redirect are covered in Configuring SSL for ASP.NET sites in Plesk and Installing SSL in Plesk. This article covers every other connection your app makes.

1. Map your app's connections

ConnectionProtect it with
Visitor's browser to your siteHTTPS, one redirect, HSTS, Secure cookies
Your app to its MSSQL databaseAn encrypted SQL connection
Your app to the mail serverSMTP on port 465 with SSL/TLS
Your app to payment gateways and APIsHTTPS with certificate validation left on
You to PleskPlesk over HTTPS on port 8443
Your computer to the server (deploys)FTP with explicit TLS on port 21

2. Browser to site: HTTPS end to end

Install the free Let's Encrypt certificate in Plesk and force HTTPS in one place: the Plesk Permanent SEO-safe 301 redirect from HTTP to HTTPS option, a web.config rewrite rule, or UseHttpsRedirection() in ASP.NET Core. Then:

  • HSTS: app.UseHsts() in production, once every address you use has a certificate.
  • Cookies: mark authentication and session cookies Secure and HttpOnly.
  • Forms and links: make every form post to an https:// or relative URL, so data is never submitted over HTTP.

For .NET Framework, the equivalent web.config rule is:

xml
<system.webServer>
  <rewrite>
    <rules>
      <rule name="Redirect to HTTPS" stopProcessing="true">
        <match url="(.*)" />
        <conditions>
          <add input="{HTTPS}" pattern="^OFF$" />
        </conditions>
        <action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" />
      </rule>
    </rules>
  </rewrite>
</system.webServer>

Use it instead of the Plesk option, not as well.

3. App to database

Current SQL Server client libraries (Microsoft.Data.SqlClient 4.0 and later) encrypt the connection by default and check the server's certificate. If the check fails, you see "the certificate chain was issued by an authority that is not trusted". The fix used on hosting is:

text
Server=DB_HOST;Database=DB_NAME;User ID=DB_USER;Password=DB_PASSWORD;TrustServerCertificate=True;

TrustServerCertificate=True keeps the connection encrypted and skips only the certificate check. Don't add Encrypt=False to silence errors. Your app reaches the database from the hosting server; the SQL Server port is closed to the outside world. Details: What to use for the MSSQL connection string.

4. App to mail server

Send through mail.yourdomain.com on port 465 with SSL/TLS from the first byte. Port 587 is closed on Windows hosting. .NET's System.Net.Mail.SmtpClient can't use port 465, so use MailKit with SecureSocketOptions.SslOnConnect. The code is in Configuring email for ASP.NET in Plesk.

5. App to payment gateways and APIs

  • Use https:// URLs only for every API your app calls.
  • Leave certificate validation on. Never set ServerCertificateCustomValidationCallback to accept any certificate, or ServicePointManager.ServerCertificateValidationCallback to return true. That turns HTTPS into an unauthenticated connection anyone in between can read.
  • Let the operating system choose the TLS version. On .NET Framework, target 4.7 or later and don't hard-code ServicePointManager.SecurityProtocol, so connections use TLS 1.2 or newer as the server supports. Modern .NET does this by default.
  • Reuse HttpClient through IHttpClientFactory in ASP.NET Core rather than creating one per request.

If an API call fails with a certificate error, check the URL and the provider's certificate, not the validation setting.

6. Payment and webhook callbacks

Payment gateways call back to your site to confirm payments. Register the callback URL with https://, verify each callback's signature as the gateway's documentation describes, and never trust an amount or status sent from the browser alone.

7. You to the server

  • Plesk: open it with the Plesk button in the client area, or at https://yourdomain.com:8443. Both use HTTPS.
  • FTP: in FileZilla or WinSCP choose Require explicit FTP over TLS on port 21. Plain FTP sends your password unencrypted. Windows hosting has no SSH or SFTP.
  • Webmail and mail apps: include webmail and mail in your Let's Encrypt certificate so those connections don't show certificate warnings.

8. Where Domain India Windows hosting fits

Every Windows plan includes free SSL, Plesk over HTTPS and FTP with explicit TLS. The cards show live prices, excluding 18% GST.

ASP Business
₹328.83/mo + GST
  • 30 GB Storage
  • 150 GB Monthly Bandwidth
  • 5 Websites
  • 50 Email Accounts
See plan details
ASP Enterprise
₹493.70/mo + GST
  • 100 GB Storage
  • Unmetered Bandwidth
  • 15 Websites
  • 100 Email Accounts
See plan details

For hardening beyond encryption, such as passwords, errors and updates, see How to secure your ASP.NET applications on Plesk.

Does an SSL certificate protect everything my ASP.NET app sends?

No. It protects the connection between visitors' browsers and your site. Your app's connections to its database, the mail server and external APIs each need their own encryption settings.

Is TrustServerCertificate=True safe for my database connection?

It keeps the connection encrypted and skips only the check of the server's certificate. For a database on the same hosting platform it is the standard setting. Never use Encrypt=False to hide errors.

Which port should my app use to send email securely?

Port 465 with SSL/TLS from the start of the connection, on mail.yourdomain.com. Port 587 is closed on Domain India Windows hosting.

How do I fix a certificate error when my app calls an API?

Check the URL and the provider's certificate, and make sure .NET Framework apps target 4.7 or later without a hard-coded TLS version. Never disable certificate validation in code.

How do I upload files securely to Windows hosting?

Use FTP on port 21 with Require explicit FTP over TLS in FileZilla or WinSCP, or the Plesk File Manager over HTTPS. SFTP is not available because Windows hosting has no SSH.

Ready to secure your ASP.NET app end to end? Compare the Windows hosting plans, or open a ticket if a TLS error won't go away. Support is on 24/7 live chat, and tickets get a first response within 15 minutes.

Secure ASP.NET hosting

Free SSL, Plesk over HTTPS and FTP with explicit TLS on every Windows plan.

See Windows hosting plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Encrypt Every Connection in Your ASP.NET App