Please use let's encrypt for ssl certificate. Add force redirect from http to https. Check and validate with sslabs service.