# Https configuration

**URL:** <https://discourse.nodered.org/t/https-configuration/84967>\
**Category:** General\
**Created:** [27 January 2024 11:28 UTC](https://discourse.nodered.org/t/https-configuration/84967 "2024-01-27T11:28:57Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![dcaccount](https://avatars.discourse-cdn.com/v4/letter/d/e36b37/32.png) [@dcaccount](https://discourse.nodered.org/u/dcaccount)\
**Post date:** [27 January 2024 11:28 UTC](https://discourse.nodered.org/t/https-configuration/84967/1 "2024-01-27T11:28:57Z")

</div>

Hello,  
following previous post and the advice got, I would like to enable https connection with Node-RED.

I have already a certificate used for my webserver, the problem is that Node-RED has not been installed with sudo so it will not be able to read this certificate.

Would you have an idea on how to solve it?  
Thanks,  
Daniele

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [27 January 2024 11:38 UTC](https://discourse.nodered.org/t/https-configuration/84967/2 "2024-01-27T11:38:28Z")

</div>

> [@dcaccount](#):
>
> I have already a certificate used for my webserver, the problem is that Node-RED has not been installed with sudo so it will not be able to read this certificate.

I would first store the certificate/key in a location that can be read (and only read) by both process's  
Say `/etc/ssl/certs`.

Then point your web server config at its location.  
And do the same for Node RED (settings.js)

```auto
https: {
    key: require("fs").readFileSync('/etc/ssl/certs/privkey.pem'),
    cert: require("fs").readFileSync('/etc/ssl/certs/cert.pem')
},

```

If required, adding `Read` access to the node-red process user shouldn't be too strenuous.  
be mindful of the `Common Name` in the cert as it may not match with the host you use for Node RED - so you might get a security warning when accessing Node RED - its more a bother than anything else

**EDIT**  
And to enforce SSL on Node RED

```auto
requireHttps: true,

```

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [27 January 2024 12:29 UTC](https://discourse.nodered.org/t/https-configuration/84967/3 "2024-01-27T12:29:24Z")

</div>

> [@dcaccount](#):
>
> I have already a certificate used for my webserver, the problem is that Node-RED has not been installed with sudo so it will not be able to read this certificate.

What web server are you using?

Configure it to work as a reverse proxy for Node-RED then you won't need to configure node-red for HTTPS.

That is by far the safest, most robust and most performant option.

---

<div class="post-metadata">

**Author:** ![dcaccount](https://avatars.discourse-cdn.com/v4/letter/d/e36b37/32.png) [@dcaccount](https://discourse.nodered.org/u/dcaccount)\
**Post date:** [27 January 2024 12:34 UTC](https://discourse.nodered.org/t/https-configuration/84967/4 "2024-01-27T12:34:22Z")

</div>

I am using lighttpd, I have no experience with reverse proxy, can you please help?

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [27 January 2024 12:38 UTC](https://discourse.nodered.org/t/https-configuration/84967/5 "2024-01-27T12:38:06Z")

</div>

I don't know `lighttpd` but whilst it does support [proxying](https://redmine.lighttpd.net/projects/lighttpd/wiki/Mod_proxy)

Just be careful about creating a potential gap for public internet traffic to hit Node RED.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [27 January 2024 12:54 UTC](https://discourse.nodered.org/t/https-configuration/84967/6 "2024-01-27T12:54:54Z")

</div>

I don't know lighttpd either but a quick search took me back to the same page that Marcus shared. You need the mod\_proxy module and it has support for proxying web sockets.

```auto
        #"upgrade" => "enable",
            # enable support for Upgrade: websocket
            # Depending on the websocket application, please also review
            # settings for server.max-read-idle and server.max-write-idle

```

---

<div class="post-metadata">

**Author:** ![dcaccount](https://avatars.discourse-cdn.com/v4/letter/d/e36b37/32.png) [@dcaccount](https://discourse.nodered.org/u/dcaccount)\
**Post date:** [28 January 2024 17:56 UTC](https://discourse.nodered.org/t/https-configuration/84967/7 "2024-01-28T17:56:13Z")

</div>

> [@marcus-j-davies](#):
>
> **EDIT**  
> And to enforce SSL on Node RED
> 
> ```auto
> requireHttps: true,
> 
> ```

Hello Marcus,  
I have created a new certificate, configured the setting.js file and it works. I have then mapped a random port XYZ to 1880, just to be on the safe side.

So, if I type:

> [https://mydomain.org](https://mydomain.org):XYZ

I reach Node-RED form the Internet.

I have then set:

```auto
requireHttps: true,

```

but if I type:

> [http://mydomain.org](http://mydomain.org):XYZ

it will not work, I get the error, Safari cannot open the page.

The same applies if I try to connect from the LAN, I need to connect typing https// otherwise it won't connect.

What am I doing wrong?  
Please advise.  
Thanks,  
Daniele

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [28 January 2024 18:06 UTC](https://discourse.nodered.org/t/https-configuration/84967/8 "2024-01-28T18:06:12Z")

</div>

> [@dcaccount](#):
>
> `requireHttps: true,`

Just stops plain text traffic - and according to notes: should redirect 🤷‍♂️

```auto
  /** The following property can be used to cause insecure HTTP connections to
     * be redirected to HTTPS.
     */
    //requireHttps: true,

```

---

<div class="post-metadata">

**Author:** ![dcaccount](https://avatars.discourse-cdn.com/v4/letter/d/e36b37/32.png) [@dcaccount](https://discourse.nodered.org/u/dcaccount)\
**Post date:** [28 January 2024 18:09 UTC](https://discourse.nodered.org/t/https-configuration/84967/9 "2024-01-28T18:09:14Z")

</div>

> [@marcus-j-davies](#):
>
> > [@dcaccount](#):
> >
> > `requireHttps: true,`
> 
> Just stops plain text traffic - and according to notes: should redirect 🤷‍♂️
> 
> ```auto
> /** The following property can be used to cause insecure HTTP connections to
> * be redirected to HTTPS.
> */
> //requireHttps: true,
> 
> ```

It should redirect but it does not seem to redirect.

By the way, now that I have set a password and an https connection, is there any risk to expose Node-RED to Internet?

In any case I will close the port and limit to LAN access, just to be safer!

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [31 January 2024 19:27 UTC](https://discourse.nodered.org/t/https-configuration/84967/10 "2024-01-31T19:27:00Z")

</div>

> [@dcaccount](#):
>
> By the way, now that I have set a password and an https connection, is there any risk to expose Node-RED to Internet?

There is always _some_ risk. Whether it is significant is hard to judge from seeing just bits of the configuration and not knowing your environment.

As previously stated, if you want to really cut down the risk, use something like CloudFlare Zero Trust which will do a lot of the heavy lifting for you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [30 April 2024 19:27 UTC](https://discourse.nodered.org/t/https-configuration/84967/11 "2024-04-30T19:27:04Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
