# Why is the Apple Touch Icon loaded via HTTP instead of HTTPS?

**URL:** https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501
**Category:** Support
**Created:** [12월 17, 2018, 9:53오후 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501 "2018-12-17T21:53:15Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 17, 2018, 9:53오후 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/1 "2018-12-17T21:53:15Z")

</div>

Every other image is loaded via HTTPS, this is the only exception.

I need to fix this in order to force HTTPS site-wide.

![Capture](https://global.discourse-cdn.com/meta/original/3X/3/3/33f69e5998e2ed74e0b4843a4bd0be38cb5fa465.png)

Am I doing something wrong?

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [12월 17, 2018, 10:12오후 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/2 "2018-12-17T22:12:03Z")

</div>

Search site settings for “http://”.

You might also have forced the image in a custom theme.

---

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 17, 2018, 10:14오후 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/3 "2018-12-17T22:14:45Z")

</div>

> [@pfaffman](#):
>
> Search site settings for “http://”.

Thanks for your reply!

This is what I get:

 ![Capture2](https://global.discourse-cdn.com/meta/original/3X/f/b/fb6e3b7b322c1dfbd28a9f1f955f2269b2d367db.png)

> [@pfaffman](#):
>
> You might also have forced the image in a custom theme.

Not sure what you mean by that. I’ve just created a new theme and added the logos, icons and favicon. All via admin settings/dashboard. That’s the only resource served via HTTP for whatever reason.

PS: Happy B’day! 🍰

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [12월 17, 2018, 10:21오후 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/4 "2018-12-17T22:21:38Z")

</div>

You might try running `/wizard` and see if that’ll let you change the logo to an https version.

---

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 17, 2018, 10:26오후 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/5 "2018-12-17T22:26:37Z")

</div>

> [@pfaffman](#):
>
> You might try running `/wizard` and see if that’ll let you change the logo to an https version.

Already tried that with no success.

If I reset the icon I get a default path for the Discourse placeholder, which is still served via HTTP:

`<link rel="apple-touch-icon" type="image/png" href="http://community.mysite.com/images/default-apple-touch-icon.png">`

---

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 17, 2018, 11:29오후 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/6 "2018-12-17T23:29:40Z")

</div>

Tested on fresh install with default themes. Still can’t fix this.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [12월 18, 2018, 12:02오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/7 "2018-12-18T00:02:44Z")

</div>

Have you tried turning on `force-https`?

---

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 18, 2018, 1:15오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/8 "2018-12-18T01:15:00Z")

</div>

> [@pfaffman](#):
>
> Have you tried turning on `force-https` ?

No. Can I _un-force_ https if I run into trouble?

---

<div class="post-metadata">

### Author: ![simon](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/simon/32/339122_2.png) [@simon](https://meta.discourse.org/u/simon)
#### Post date: [12월 18, 2018, 1:24오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/9 "2018-12-18T01:24:50Z")

</div>

> [@Graphiwiz](#):
>
> Can I _un-force_ https if I run into trouble?

Yes, you can disable the ‘force https’ setting by unchecking the setting. If for some reason enabling the setting locks you out of your site, you can disable it through the rails console with:

```plaintext
SiteSetting.force_https = false

```

---

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 18, 2018, 2:25오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/10 "2018-12-18T02:25:26Z")

</div>

> [@simon](#):
>
> Yes, you can disable the ‘force https’ setting by unchecking the setting. If for some reason enabling the setting locks you out of your site, you can disable it through the rails console with:

After forcing https, it seems to be working now, I get no errors but there seems to be an issue for the security certificate though.

I get this in Firefox only when accessing [https://WWW.community.mysite.com](https://WWW.community.mysite.com):

`The certificate is only valid for community.mysite.com. Error code: SSL_ERROR_BAD_CERT_DOMAIN`

Note that the following work perfectly (ALL redirect to [https://community.mysite.com](https://community.mysite.com), except [https://www](https://www) in FF):

- [https://community.mysite.com](https://community.mysite.com)
- [www.community.mysite.com](http://www.community.mysite.com)
- [community.mysite.com](http://community.mysite.com)
- [http://community.mysite.com](http://community.mysite.com)
- [http://www.community.mysite.com](http://www.community.mysite.com)

Although [https://WWW.community.mysite.com](https://WWW.community.mysite.com) also redirects to [https://community.mysite.com](https://community.mysite.com) in Chrome and it works as expected, Firefox does **not** redirect and instead shows that error and blocks the site.

I configured my `app.yml` file using this guide: [Set up Let’s Encrypt with multiple domains / redirects](https://meta.discourse.org/t/setting-up-let-s-encrypt-with-multiple-domains/56685) and added a redirect from www to the non-www version following this guide: [(Superseded) Redirect additional domain(s) to your Discourse instance](https://meta.discourse.org/t/redirect-single-multiple-domain-s-to-your-discourse-instance/18492)

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [12월 18, 2018, 2:37오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/11 "2018-12-18T02:37:43Z")

</div>

Yep, you can’t publish over HTTPS reliably without that setting being enabled. It’s why it warns you every time you visit the dashboard that it has to be set.

As you’ve not shared your site URL we can’t look at the certificate to verify if you’ve configured it correctly, but that error suggests you’ve missed a subject alternate name. It’s only going to be used for the redirect, but once you’ve corrected your certificate the error will go away.

---

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 18, 2018, 2:45오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/12 "2018-12-18T02:45:27Z")

</div>

> [@Stephen](#):
>
> that error suggests you’ve missed a subject alternate name. It’s only going to be used for the redirect, but once you’ve corrected your certificate the error will go away.

Thanks for your input.

So essentially I should add a redirect from the [https://www](https://www) version to https:// – is that what you’re implying?

EDIT: Just wanted to stress that the [https://www](https://www) is currently only redirecting to https:// in Chrome. Firefox is blocking the site.

Currently I only have this redirect:

```
- file:
    path: /etc/nginx/conf.d/discourse_redirect_1.conf
    contents: |
      server {
        listen 80;
        server_name www.community.example.com;
        return 301 $scheme://community.example.com$request_uri;
      }

```

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [12월 18, 2018, 2:52오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/13 "2018-12-18T02:52:42Z")

</div>

I’m not implying anything, if you’re getting an HTTPS error for www that means you’ve configured a server directive to listen on an HTTPS URL, but the associated certificate lacks the **S** ubject **A** lternate **N** ame for WWW. Your Let’s Encrypt request will need to request any additional domains passed in using -d as specified in the guide you linked above:

```
 after_ssl:
- replace:
    filename: "/etc/runit/1.d/letsencrypt"
    from: /-k 4096 -w \/var\/www\/discourse\/public/
    to: |
      -d www.main-domain.com -d second-domain.com -d www.second-domain.com -d other-domain.com -d www.other-domain.com -k 4096 -w /var/www/discourse/public

- replace:
    filename: "/etc/runit/1.d/letsencrypt"
    from: /-k 4096 --force -w \/var\/www\/discourse\/public/
    to: |
      -d www.main-domain.com -d second-domain.com -d www.second-domain.com -d other-domain.com -d www.other-domain.com -k 4096 --force -w /var/www/discourse/public

```

With the real production domain names specified in place of the examples. I can’t check the state of the certificate you’re using as you’ve not provided any real link to your site.

This will only be for the redirect as you can’t publish Discourse itself via multiple URLs. Strictly speaking you shouldn’t need a server directive at all for [https://www](https://www).\* unless for some reason you published that URL at some point. If you didn’t then you’re over-engineering your configuration.

---

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 18, 2018, 2:59오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/14 "2018-12-18T02:59:32Z")

</div>

Interesting but I don’t understand why it’s working in Chrome perfectly and only FF is displaying the error.

Here is my `app.yml` ssl config:

```
  after_ssl:
    - replace:
        filename: "/etc/runit/1.d/letsencrypt"
        from: /-k 4096 -w \/var\/www\/discourse\/public/
        to: |
          -d www.example.com -d www.community.example.com -d example.com -d community.example.com -k 4096 -w /var/www/discourse/public

    - replace:
        filename: "/etc/runit/1.d/letsencrypt"
        from: /-k 4096 --force -w \/var\/www\/discourse\/public/
        to: |
           -d www.example.com -d www.community.example.com -d example.com -d community.example.com -k 4096 --force -w /var/www/discourse/public

    - replace:
        filename: "/etc/nginx/conf.d/discourse.conf"
        from: /return 301 https.+/
        to: |
        return 301 https://$host$request_uri;

    - replace:
         filename: "/etc/nginx/conf.d/discourse.conf"
         from: /gzip on;[^\}]+\}/m
         to: |
         gzip on;
         add_header Strict-Transport-Security 'max-age=31536000';

```

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [12월 18, 2018, 3:03오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/15 "2018-12-18T03:03:00Z")

</div>

I’m sorry, without real details for the site to troubleshoot you’re probably on your own here.

There are ways to step through the problem and identify the cause, but we can’t even begin to employ such methods when you’re artificially limiting and redacting aspects of your setup.

---

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 18, 2018, 3:05오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/16 "2018-12-18T03:05:20Z")

</div>

The only thing I masked was the actual website name: `example`. The rest of the details are not redacted in any way.

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [12월 18, 2018, 3:06오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/17 "2018-12-18T03:06:47Z")

</div>

They are, because I can’t inspect the headers and redirects to a fictional URL. Good luck resolving this anyhow.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [12월 18, 2018, 3:09오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/18 "2018-12-18T03:09:05Z")

</div>

Are you using Cloudflare or some other “magically add HTTPS through trickery” service?

---

<div class="post-metadata">

### Author: ![Graphiwiz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/graphiwiz/32/126393_2.png) [@Graphiwiz](https://meta.discourse.org/u/Graphiwiz)
#### Post date: [12월 18, 2018, 3:10오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/19 "2018-12-18T03:10:47Z")

</div>

> [@codinghorror](#):
>
> Are you using Cloudflare or some other “magically add HTTPS through trickery” service?

No, I am not. Absolutely no magic tricks.

---

<div class="post-metadata">

### Author: ![brahn](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/brahn/32/109267_2.png) [@brahn](https://meta.discourse.org/u/brahn)
#### Post date: [12월 18, 2018, 3:11오전 UTC](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501/20 "2018-12-18T03:11:03Z")

</div>

Your symptoms are implying that firefox is being case sensitive where Chrome is not. If you add a WWW version to the let’s encrypt domain list does that make Firefox happy?

[다음 페이지](https://meta.discourse.org/t/why-is-the-apple-touch-icon-loaded-via-http-instead-of-https/104501.md?page=2)
