diff --git a/ssl/provision_ssl.drush.inc b/ssl/provision_ssl.drush.inc
index 01846e5..27a6328 100644
--- a/ssl/provision_ssl.drush.inc
+++ b/ssl/provision_ssl.drush.inc
@@ -18,6 +18,8 @@
  *
  * php_value session.cookie_secure 1
  * SSLEngine On
+ * SSLCertificateFile $AEGIR_HOME/config/ssl.d/<cert>.pem
+ * SSLCertificateKeyFile $AEGIR_HOME/config/ssl.d/<cert>.key
  */
 function provision_ssl_provision_apache_vhost_config($url, $options) {
   if (!empty($options['ssl'])) {
@@ -31,10 +33,15 @@ function provision_ssl_provision_apache_vhost_config($url, $options) {
       $newoptions['site_port'] = 80;
       provision_write_config(drush_get_option('vhost_path') . '/' . $url . '_80', _provision_apache_redirect_template(), $newoptions);
     }
-    $newoptions = $options;
-    $newoptions['site_port'] = 443;
-    $newoptions['extra_config'] = "php_value session.cookie_secure 1\nSSLEngine On\n";
-    provision_write_config(drush_get_option('vhost_path') . '/' . $url .  '_443', _provision_apache_default_template(), $newoptions);
+    else {
+      // enable default port 80 if there's no redirect
+      // make sure that http and https work simultaneously
+      $newoptions = $options;
+      $newoptions['site_port'] = 80;
+      provision_write_config(drush_get_option('vhost_path') . '/' . $url . '_80', _provision_apache_default_template(), $newoptions);
+    }
+
+    return _provision_ssl_generate_ssl_vhost_extra($url, $options);
   }
   return NULL;
 }
@@ -42,10 +49,43 @@ function provision_ssl_provision_apache_vhost_config($url, $options) {
 /**
  * Implementation of hook_provision_apache_delete_vhost()
  *
- * This will delete the redirection vhost if it was created.
+ * This will delete any vhost created in conjunction with the ssl vhost.
  */
 function provision_ssl_provision_apache_delete_vhost($url, $options) {
-  if ($options['ssl'] && $options['ssl_redirect']) {
+  if ($options['ssl']) {
     provision_path('unlink', drush_get_option('vhost_path') . '/' . $url . '_80', TRUE, NULL, dt("Failed deleting redirection vhost."));
   }
 }
+
+/**
+ * Add additional SSL directives to vhost extra_config.
+ */
+function _provision_ssl_generate_ssl_vhost_extra($url, $options) {
+  $lines = array("php_value session.cookie_secure 1", "SSLEngine On");
+  $ssl_dir = drush_get_option('config_path') . "/ssl.d";
+  if (! provision_path('exists', $ssl_dir)) {
+    provision_path('mkdir', $ssl_dir);
+    drush_log(dt("SSL config directory is newly created.  Make sure to put your certificates in %ssl_dir.", array('%ssl_dir' => $ssl_dir)));
+  }
+
+  if (!$options['ssl_wildcard']) {
+    // use individual certificates per site
+    if (file_exists("$ssl_dir/$url.pem") && file_exists("$ssl_dir/$url.key")) {
+      $lines[] = "SSLCertificateFile " . "$ssl_dir/$url.pem";
+      $lines[] = "SSLCertificateKeyFile " . "$ssl_dir/$url.key";
+    } else {
+      drush_log(dt("cannot find SSL certificates %cert or %key, using server-wide wildcard", array('%cert' => "$ssl_dir/$url.crt", '%key' => "$ssl_dir/$url.key")));
+    }
+  }
+  else {
+    // use the server-wide certificate
+    $server_wide_url = $options['web_host'];
+    if (file_exists("$ssl_dir/$server_wide_url.pem") && file_exists("$ssl_dir/$server_wide_url.key")) {
+      $lines[] = "SSLCertificateFile " . "$ssl_dir/$server_wide_url.pem";
+      $lines[] = "SSLCertificateKeyFile " . "$ssl_dir/$server_wide_url.key";
+    } else {
+      drush_log(dt("cannot find SSL certificates %cert or %key, using server-wide wildcard", array('%cert' => "$ssl_dir/$server_wide_url.crt", '%key' => "$ssl_dir/$server_wide_url.key")));
+    }
+  }
+  return $lines;
+}
\ No newline at end of file
diff --git a/ssl/verify.provision.inc b/ssl/verify.provision.inc
index 626eb34..66d541d 100644
--- a/ssl/verify.provision.inc
+++ b/ssl/verify.provision.inc
@@ -5,5 +5,6 @@
 function drush_provision_ssl_post_provision_verify($url = NULL) {
   if (PROVISION_CONTEXT_SITE) {
     drush_set_option('ssl', drush_get_option('ssl'), 'site');
+    drush_set_option('ssl_wildcard', drush_get_option('ssl_wildcard'), 'site');
   }
 }
