# How to install Tasmota on an ESP8266

**URL:** <https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587>\
**Category:** Share Your Projects\
**Tags:** node-red-dashboard, function-node, mqtt\
**Created:** [7 June 2022 19:06 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587 "2022-06-07T19:06:29Z")\
**Posts on this page:** 20\
**Page:** 3

<div class="post-metadata">

**Author:** ![9toejack](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/9toejack/32/56868_2.png) [@9toejack](https://discourse.nodered.org/u/9toejack)\
**Post date:** [10 June 2022 16:39 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/41 "2022-06-10T16:39:53Z")

</div>

May be silly what is SSO.  
also I'm thinking of doing the admin seat it may be the better option for what I'm trying to do.

 ![pricing](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/5/d54eefea592d01c6be5e03b0d002c2396323d637.png)

---

<div class="post-metadata">

**Author:** ![zenofmud](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/zenofmud/32/316_2.png) [@zenofmud](https://discourse.nodered.org/u/zenofmud)\
**Post date:** [10 June 2022 17:15 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/42 "2022-06-10T17:15:45Z")

</div>

> [@9toejack](#):
>
> what is SSO.

> **[What is Single Sign-On (SSO) and How Does It Work?](https://www.techtarget.com/searchsecurity/definition/single-sign-on)**
>
> Discover what single sign-on is and how it enables users to log in to multiple accounts without having to remember a different password for each.

---

<div class="post-metadata">

**Author:** ![9toejack](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/9toejack/32/56868_2.png) [@9toejack](https://discourse.nodered.org/u/9toejack)\
**Post date:** [10 June 2022 19:03 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/43 "2022-06-10T19:03:56Z")

</div>

Ty you will look at after dr. Appt

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [11 June 2022 03:03 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/44 "2022-06-11T03:03:18Z")

</div>

Now that you have got the two units connected (presumably on Zerotier) then you can use NR from the remote device across the link as if you are there

From your remote device - bring up a browser and [http://TheVirtual](http://TheVirtual) IP Address of the PI/1880/ui and you are away

This is a virtual network that only the devices that you give permission to can access.

If you have enabled login securtiy on your NR then you will be presented with the usual login screen

Craig

---

<div class="post-metadata">

**Author:** ![krambriw](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/krambriw/32/5429_2.png) [@krambriw](https://discourse.nodered.org/u/krambriw)\
**Post date:** [11 June 2022 04:35 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/45 "2022-06-11T04:35:42Z")

</div>

Since a lot is discussed about Zerotier I'm just curious if anybody knows the details of the security it provides? I understand it is using encryption for communication but we have learrned that when using VPN connections it is maybe not enough, how about certificate handling? Are there both client and server certificates involved when establishing connections and are they updated on a regular basis? Anybody knows?

Best regards, Walter

---

<div class="post-metadata">

**Author:** ![9toejack](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/9toejack/32/56868_2.png) [@9toejack](https://discourse.nodered.org/u/9toejack)\
**Post date:** [11 June 2022 04:40 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/46 "2022-06-11T04:40:07Z")

</div>

Yes I tried that, it works.  
as far as nr security i still need to read that a third time before i start messing with it.  
cheers.

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [11 June 2022 06:01 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/47 "2022-06-11T06:01:45Z")

</div>

OK good one - so now you have a secured tunnel to your NR and can turn off anything in the firewalls/waps where you were allowing traffic into the Pi

Obviously any other machines you want to access (or use to access the PI) you just run the same process and add them into the Virtual network you have created

Craig

---

<div class="post-metadata">

**Author:** ![9toejack](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/9toejack/32/56868_2.png) [@9toejack](https://discourse.nodered.org/u/9toejack)\
**Post date:** [11 June 2022 06:39 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/48 "2022-06-11T06:39:43Z")

</div>

yes , like my cell phone, and my 3 laptops.  
but as of now it doesnt ask for a password with zerotier.  
but will when i have set up correctly in nodered.  
next question is how to have others be able to do the same thing so they can brew a beer with me!

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [11 June 2022 11:53 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/49 "2022-06-11T11:53:44Z")

</div>

> [@krambriw](#):
>
> about Zerotier I'm just curious if anybody knows the details of the security it provides?

Had a quick look but I'm not sure I'm any the wiser. I did spot that they recommend running a higher-level security over Zerotier such as SSH. So clearly there are limitations. I wouldn't want to rely on it for anything commercial without a deeper dive into it personally. But for low-value home automation it seems fine as far as I can tell so far.

---

<div class="post-metadata">

**Author:** ![krambriw](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/krambriw/32/5429_2.png) [@krambriw](https://discourse.nodered.org/u/krambriw)\
**Post date:** [11 June 2022 12:39 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/50 "2022-06-11T12:39:17Z")

</div>

Hello Julian, yes, agree, for low-value hoe automations I think is fine. It is in a way "the same thinking" with connections to MS Azure. As example, static connection strings would probaply by fine for the same type of low-value application but not for production systems in commercial or business oriented applications. I heard the best then would be if the device itself would have a TPM 2.0 hw chip (Trusted Platform Module) on board.

Would anyway be interesting to know if Zerotier is using a static setup or if it is auto updated/changed periodically

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [11 June 2022 12:54 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/51 "2022-06-11T12:54:35Z")

</div>

> [@krambriw](#):
>
> It is in a way "the same thinking" with connections to MS Azure.

For enterprise-grade IoT, I'd want isolated LAN's fed through a VPN to Azure (unless you have ExpressRoute on-site).

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [11 June 2022 16:07 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/52 "2022-06-11T16:07:46Z")

</div>

just 2 infos about zerotier.

1. If you want to revalidate your Pi with a new identity, you have to run these 3 commands:

```auto
sudo systemctl stop zerotier-one
sudo rm /var/lib/zerotier-one/identity.*
sudo systemctl start zerotier-one

```

1. Web pages embedded in another web page do not work. They are blocked by the browser when viewed via the zerotier IP.

This is a very good tool for everyday use.

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [12 June 2022 07:09 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/53 "2022-06-12T07:09:34Z")

</div>

Here is the link to the manual that provides details about the security as implemented

It does a couple of things - but the main one is

```auto
Asymmetric public key encryption is Curve25519/Ed25519, a 256-bit elliptic curve variant.

Every VL1 packet is encrypted end to end using (as of the current version) 256-bit Salsa20 and authenticated using the Poly1305 message authentication (MAC) algorithm. MAC is computed after encryption (encrypt-then-MAC) and the cipher/MAC composition used is identical to the NaCl reference implementation.

As of today we do not implement forward secrecy or other stateful cryptographic features in VL1. We don’t do this for the sake of simplicity, reliability, and code footprint, and because frequently changing state makes features like clustering and fail-over much harder to implement. See our discussion on GitHub.

```

Craig

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [12 June 2022 07:14 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/54 "2022-06-12T07:14:17Z")

</div>

to allow others to join (once you have secured your PI) - you can login to your Zerotier central and send them and invite which provides a link to your network number and links to download and install the software - if is fairly straightforward if they are 1/2 way computer literate.

Once they confirm to you that they have downloaded the software and joined the network - you go back into your Zerotier Contrl panel and authorise them as a node on your virtual network.

If you want to be more secure you can create an additional network for others to attach to (your devices can attach to more than one network at a time) - you then attach your PI to the 2nd network and invite them to join that network - this way they can not see any of your devices (there is no routing between ZT networks unless you specifically allow it) so no one can use this link as a jumping off point to try and attack your home PC etc

You can also delve down further into the network definitions and lock down specific ports etc that you will allow across there (and nothing else)

Craig

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 June 2022 14:26 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/55 "2022-06-12T14:26:33Z")

</div>

> [@craigcurtin](#):
>
> Here is the link to the manual that provides details about the security as implemented

Yes, that is why I was non-the-wiser after reading it! It really doesn't actually tell you much of practical use.

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [12 June 2022 22:30 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/56 "2022-06-12T22:30:51Z")

</div>

Well it does tell you it is 256 bit !! I guess you could delve into the source code if you were that interested !! 😂 😂

---

<div class="post-metadata">

**Author:** ![krambriw](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/krambriw/32/5429_2.png) [@krambriw](https://discourse.nodered.org/u/krambriw)\
**Post date:** [13 June 2022 05:45 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/57 "2022-06-13T05:45:08Z")

</div>

> As of today we do not implement forward secrecy or other stateful cryptographic features in VL1. We don’t do this for the sake of simplicity, reliability, and code footprint, and because frequently changing state makes features like clustering and fail-over much harder to implement

Doesn't this say that things are pretty static even if it is encrypted? No dynamic changes of keys or certificates etc

---

<div class="post-metadata">

**Author:** ![hominidae](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hominidae/32/4174_2.png) [@hominidae](https://discourse.nodered.org/u/hominidae)\
**Post date:** [14 June 2022 08:31 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/58 "2022-06-14T08:31:18Z")

</div>

> [@craigcurtin](#):
>
> Now that you have got the two units connected (presumably on Zerotier) then you can use NR from the remote device across the link as if you are there

...as zt receives a lot of attention here, maybe it is worth to point out that wireguard is another option.  
Mind you that a wireguard network is a mesh, not a standard client server solution - although people still conceive it as one).  
wireguard is getting more and more implemented in standard ISP router appliances, like mikrotik RouterOS (well also zt, here - and in Germany even AVM FritzOS has wireguard now).

---

<div class="post-metadata">

**Author:** ![WBr](https://avatars.discourse-cdn.com/v4/letter/w/b3f665/32.png) [@WBr](https://discourse.nodered.org/u/WBr)\
**Post date:** [19 July 2022 18:25 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/59 "2022-07-19T18:25:35Z")

</div>

> [@9toejack](#):
>
> tasmotizer and installing Tasmota

I am starting the installation precedure via the website ([Install Tasmota](https://tasmota.github.io/install/)) but what is the difference between tasmotizer and Tasmota?

---

<div class="post-metadata">

**Author:** ![WBr](https://avatars.discourse-cdn.com/v4/letter/w/b3f665/32.png) [@WBr](https://discourse.nodered.org/u/WBr)\
**Post date:** [19 July 2022 18:34 UTC](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587/60 "2022-07-19T18:34:25Z")

</div>

> [@9toejack](#):
>
> However you have to install minimal Tasmota first

From that web browser link right? The link from my previous post? just above this one?

After the webbrowser thing:

> [@9toejack](#):
>
> then you can update with this one.

this doesn't work

[Previous page](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587.md?page=2)

[Next page](https://discourse.nodered.org/t/how-to-install-tasmota-on-an-esp8266/63587.md?page=4)
