# Encrypt msg payload

**URL:** <https://discourse.nodered.org/t/encrypt-msg-payload/87085>\
**Category:** General\
**Created:** [8 April 2024 20:49 UTC](https://discourse.nodered.org/t/encrypt-msg-payload/87085 "2024-04-08T20:49:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![donsay](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@donsay](https://discourse.nodered.org/u/donsay)\
**Post date:** [8 April 2024 20:49 UTC](https://discourse.nodered.org/t/encrypt-msg-payload/87085/1 "2024-04-08T20:49:22Z")

</div>

Hi.

I'm doing an Http 'put' into my NodeRed app. The source is JavaScript on an html page. I've encrypted the 'body' with Crypto-JS, but now I see that's pretty old and has some vulnerabilities. Is there another encryption method that can be implemented in client-side JavaScript, and decrypted in NodeRed?

I did some googling, but I'm not sure what I'm looking for.

Thanks.  
Don

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [9 April 2024 08:19 UTC](https://discourse.nodered.org/t/encrypt-msg-payload/87085/2 "2024-04-09T08:19:49Z")

</div>

Use https then it will be encrypted automatically.

---

<div class="post-metadata">

**Author:** ![donsay](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@donsay](https://discourse.nodered.org/u/donsay)\
**Post date:** [27 May 2024 21:49 UTC](https://discourse.nodered.org/t/encrypt-msg-payload/87085/3 "2024-05-27T21:49:01Z")

</div>

Colin, that would be the goal. Unfortunately, we don't have a cert on the Pi (complicated...), so we can't do https.

---

<div class="post-metadata">

**Author:** ![kitori](https://avatars.discourse-cdn.com/v4/letter/k/f08c70/32.png) [@kitori](https://discourse.nodered.org/u/kitori)\
**Post date:** [28 May 2024 06:28 UTC](https://discourse.nodered.org/t/encrypt-msg-payload/87085/4 "2024-05-28T06:28:35Z")

</div>

You can use DNS for issuing a cert.

> **[dnsapi](https://github.com/acmesh-official/acme.sh/wiki/dnsapi)**
>
> A pure Unix shell script implementing ACME client protocol - acmesh-official/acme.sh

---

<div class="post-metadata">

**Author:** ![donsay](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@donsay](https://discourse.nodered.org/u/donsay)\
**Post date:** [29 May 2024 03:22 UTC](https://discourse.nodered.org/t/encrypt-msg-payload/87085/5 "2024-05-29T03:22:37Z")

</div>

Thanks. I'll check it out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [27 August 2024 03:23 UTC](https://discourse.nodered.org/t/encrypt-msg-payload/87085/6 "2024-08-27T03:23:21Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
