# How to secure node-red with https access

**URL:** <https://discourse.nodered.org/t/how-to-secure-node-red-with-https-access/84168>\
**Category:** General\
**Tags:** http-request, security\
**Created:** [1 January 2024 06:04 UTC](https://discourse.nodered.org/t/how-to-secure-node-red-with-https-access/84168 "2024-01-01T06:04:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![f5swb](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@f5swb](https://discourse.nodered.org/u/f5swb)\
**Post date:** [1 January 2024 06:04 UTC](https://discourse.nodered.org/t/how-to-secure-node-red-with-https-access/84168/1 "2024-01-01T06:04:37Z")

</div>

Hello to all !  
I try to put my node red access in https but I can't succeed.

1 Jan 07:11:33 - [info] Node-RED version: v3.1.3  
1 Jan 07:11:33 - [info] Node.js version: v20.10.0  
1 Jan 07:11:33 - [info] Linux 6.1.69-v8+ arm64 LE

OpenSSL 3.0.11 19 Sep 2023 (Library: OpenSSL 3.0.11 19 Sep 2023)

What I did : [https://dave.thwaites.org.uk/theatre-royal/eos-remote/securing-nodered.html](https://dave.thwaites.org.uk/theatre-royal/eos-remote/securing-nodered.html)

When I start node-red-start I have this in the log :

Error loading settings file: /home/hotspot/.node-red/settings.js  
Error: EACCES: permission denied, open '/home/hotspot/.node-red/public/privatekey.pem'

I have a public and inside I have :

:/home/hotspot/.node-red/public# ls  
certificate.pem myCA.cer myCA.key private-csr.req privatekey.pem

In the settings.js :  
/\*\* Option 1: static object \*/  
https: {  
key: require("fs").readFileSync('/home/hotspot/.node-red/public/privatekey.pem'),  
cert: require("fs").readFileSync('/home/hotspot/.node-red/certificate.pem')  
},

requireHttps: true,

Any help will be very appreciated my friends 🙂

Best regards and a happy new year 2024 to all !

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [1 January 2024 06:41 UTC](https://discourse.nodered.org/t/how-to-secure-node-red-with-https-access/84168/2 "2024-01-01T06:41:21Z")

</div>

> [@f5swb](#):
>
> Error: EACCES: permission denied

Ensure the account which runs node-red has read access to the files.

---

<div class="post-metadata">

**Author:** ![f5swb](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@f5swb](https://discourse.nodered.org/u/f5swb)\
**Post date:** [1 January 2024 06:42 UTC](https://discourse.nodered.org/t/how-to-secure-node-red-with-https-access/84168/3 "2024-01-01T06:42:44Z")

</div>

ok steve I check it now

---

<div class="post-metadata">

**Author:** ![f5swb](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@f5swb](https://discourse.nodered.org/u/f5swb)\
**Post date:** [1 January 2024 06:53 UTC](https://discourse.nodered.org/t/how-to-secure-node-red-with-https-access/84168/4 "2024-01-01T06:53:29Z")

</div>

it means that all the files are only in a root access

ls -l  
total 20  
-rw-r--r-- 1 root root 916 Jan 1 06:51 certificate.pem  
-rw-r--r-- 1 root root 1107 Jan 1 06:49 myCA.cer  
-rw------- 1 root root 1704 Jan 1 06:49 myCA.key  
-rw-r--r-- 1 root root 676 Jan 1 06:51 private-csr.req  
-rw------- 1 root root 916 Jan 1 06:49 privatekey.pem

question 1 : but I have created this file not in a root session and without sudo command ?  
question 2 : the node red isn't installed in root session but in a standart as pi (hotspot in my case) session ?

Many thanks for your help 🙂

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [1 January 2024 07:07 UTC](https://discourse.nodered.org/t/how-to-secure-node-red-with-https-access/84168/5 "2024-01-01T07:07:03Z")

</div>

> [@f5swb](#):
>
> question 1 : but I have created this file not in a root session and without sudo command

No idea

> [@f5swb](#):
>
> question 2 : the node red isn't installed in root session but in a standart as pi (hotspot in my case) session

Just `chown` the files and be done 😄

---

<div class="post-metadata">

**Author:** ![f5swb](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@f5swb](https://discourse.nodered.org/u/f5swb)\
**Post date:** [1 January 2024 07:25 UTC](https://discourse.nodered.org/t/how-to-secure-node-red-with-https-access/84168/6 "2024-01-01T07:25:11Z")

</div>

so easy many thanks steve 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [15 January 2024 07:25 UTC](https://discourse.nodered.org/t/how-to-secure-node-red-with-https-access/84168/7 "2024-01-15T07:25:54Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
