# I don't want to use HTTPS

**URL:** <https://help.nextcloud.com/t/i-dont-want-to-use-https/3969>\
**Category:** ℹ️ Support\
**Created:** [October 7, 2016, 4:15pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969 "2016-10-07T16:15:52Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![drewgreat](https://help.nextcloud.com/user_avatar/help.nextcloud.com/drewgreat/32/6070_2.png) [@drewgreat](https://help.nextcloud.com/u/drewgreat)\
**Post date:** [October 7, 2016, 4:15pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/1 "2016-10-07T16:15:52Z")

</div>

I know, HTTPS is important for security. I get that. I want to use a proxy server to apply HTTPS outside of Nextcloud (because I have multiple services on my network which need to respond to requests on 443).

I’ve already configured Nextcloud and the proxy server and everything is working. I’ve added other services and now have problems with Nextcloud. I’m trying to debug and it’s very difficult because when I try to access my Nextcloud directly (without the proxy) by visiting [http://nextcloud.internal.ip.address](http://nextcloud.internal.ip.address) the browser is being redirected to [https://nextcloud.internal.ip.address/login](https://nextcloud.internal.ip.address/login). Of course that’s not working because the web server isn’t set to listen to 443. I never setup Nextcloud to force HTTPS, and there’s nothing in config.php which would cause it to.

I’m using nginx for the proxy and the main server, there’s nothing in the main server config to respond to SSL requests and the main proxy is turned off for the time being.

If I configure a different domain to point to nextcloud.internal.ip.address I’m taken to the trusted domain webpage, but when I click to add the domain it redirects my request to the https:// version (which doesn’t respond because the server isn’t setup to listen to 443). I’m guessing things were working before because I had configured the SSL proxy and everything was coming through it so random https redirects didn’t hurt anything.

How do I make Nextcloud NEVER force HTTPS?

---

<div class="post-metadata">

**Author:** ![Guillaume](https://help.nextcloud.com/letter_avatar/guillaume/32/5_5575768a8748004e209b776fc1b2916d.png) [@Guillaume](https://help.nextcloud.com/u/Guillaume)\
**Post date:** [October 7, 2016, 4:29pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/2 "2016-10-07T16:29:28Z")

</div>

hello,  
from my point of view, this redirection is due to the NGINX configuration files. Did you check the /etc/nginx/conf.d/_.conf or /etc/nginx/sites-available/_.conf ?  
you should find something like that:

server {  
listen 80 default\_server;  
server\_name your\_domain.fr www.your\_domain.fr;

# enforce https

return 301 https://$server\_name$request\_uri;  
}

which is the cause of your redirection …

---

<div class="post-metadata">

**Author:** ![drewgreat](https://help.nextcloud.com/user_avatar/help.nextcloud.com/drewgreat/32/6070_2.png) [@drewgreat](https://help.nextcloud.com/u/drewgreat)\
**Post date:** [October 7, 2016, 4:32pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/3 "2016-10-07T16:32:11Z")

</div>

Yep, that’s exactly how my proxy server is configured however like I said the proxy server is turned off and I’m accessing Nextcloud directly. It behaved like this the moment I installed it but I never thought anything of it because it was going to be https proxied anyway.

The nginx conf file for the Nextcloud server has 1 listen directive and it’s listening to 80.

---

<div class="post-metadata">

**Author:** ![Guillaume](https://help.nextcloud.com/letter_avatar/guillaume/32/5_5575768a8748004e209b776fc1b2916d.png) [@Guillaume](https://help.nextcloud.com/u/Guillaume)\
**Post date:** [October 7, 2016, 5:06pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/4 "2016-10-07T17:06:50Z")

</div>

did you enable HSTS ?  
if yes, try access using another browser …

---

<div class="post-metadata">

**Author:** ![drewgreat](https://help.nextcloud.com/user_avatar/help.nextcloud.com/drewgreat/32/6070_2.png) [@drewgreat](https://help.nextcloud.com/u/drewgreat)\
**Post date:** [October 7, 2016, 6:28pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/5 "2016-10-07T18:28:14Z")

</div>

The proxy uses HSTS but the internal IP shouldn’t have an HSTS record. Further if I try to navigate to [http://ip.address/login](http://ip.address/login) it works, it won’t log in because it insists on redirecting to https to log in, but it doesn’t redirect every request. I suspect something in the code base is causing the redirect for some instructions.

Regardless I did try a new browser, same behavior.

---

<div class="post-metadata">

**Author:** ![drewgreat](https://help.nextcloud.com/user_avatar/help.nextcloud.com/drewgreat/32/6070_2.png) [@drewgreat](https://help.nextcloud.com/u/drewgreat)\
**Post date:** [October 10, 2016, 3:41pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/6 "2016-10-10T15:41:44Z")

</div>

I figured it out. Turns out I need to work on the old reading comprehension.

[https://docs.nextcloud.com/server/9/admin\_manual/installation/nginx\_examples.html](https://docs.nextcloud.com/server/9/admin_manual/installation/nginx_examples.html) says

> Remove fastcgi\_params HTTPS on;

I hadn’t done that, now it works perfect!

---

<div class="post-metadata">

**Author:** ![sealionking](https://help.nextcloud.com/user_avatar/help.nextcloud.com/sealionking/32/14278_2.png) [@sealionking](https://help.nextcloud.com/u/sealionking)\
**Post date:** [March 30, 2019, 3:28am UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/7 "2019-03-30T03:28:23Z")

</div>

thanks very much

comments out the line saved me.

---

<div class="post-metadata">

**Author:** ![Michael\_Davydov](https://help.nextcloud.com/user_avatar/help.nextcloud.com/michael_davydov/32/14328_2.png) [@Michael\_Davydov](https://help.nextcloud.com/u/Michael_Davydov)\
**Post date:** [December 5, 2019, 2:26pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/8 "2019-12-05T14:26:03Z")

</div>

I did that, however it still redirects me to https during login ☹ Same as you, on internal IP, with nginx serving it on port 80

---

<div class="post-metadata">

**Author:** ![ynoote](https://help.nextcloud.com/letter_avatar/ynoote/32/5_5575768a8748004e209b776fc1b2916d.png) [@ynoote](https://help.nextcloud.com/u/ynoote)\
**Post date:** [December 12, 2019, 10:17am UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/9 "2019-12-12T10:17:26Z")

</div>

It’s same to me.

I tried to

1. session.cookie\_secure = off(on php-fpm)  
php\_admin\_flag[session.cookie\_secure] = off
2. remove `fastcgi_params HTTPS on;`
3. rewrite nginx.conf

From

server {  
listen 443 ssl http2;  
listen [::]:443 ssl http2;

To

server {  
listen 80;  
listen [::]:80;

But When I enter ID/PW to log in,  
Redirect to Login Page.

Debug Tools tel ‘[http://xxxxxx/apps/files/](http://xxxxxx/apps/files/)’ has no responce  
Error log line is "GET /apps/files/ HTTP/1.1 303 0 "

---

<div class="post-metadata">

**Author:** ![ynoote](https://help.nextcloud.com/letter_avatar/ynoote/32/5_5575768a8748004e209b776fc1b2916d.png) [@ynoote](https://help.nextcloud.com/u/ynoote)\
**Post date:** [December 13, 2019, 3:11am UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/10 "2019-12-13T03:11:37Z")

</div>

it work fine to me!

add changes the following steps.

1. delete nginx add\_header!  
`add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload;";`

2. restart everything

restart php-fpm  
restart nginx  
restart redis

1. Browse in secret mode

start Chrome with secret mode.

That’s done.

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [November 6, 2024, 8:52pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/11 "2024-11-06T20:52:43Z")

</div>

wwe: close old topics

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [January 24, 2025, 6:26pm UTC](https://help.nextcloud.com/t/i-dont-want-to-use-https/3969/12 "2025-01-24T18:26:03Z")

</div>


