# Making connection secure (HTTPS) in Windows

**URL:** <https://discourse.nodered.org/t/making-connection-secure-https-in-windows/83601>\
**Category:** General\
**Tags:** security, windows\
**Created:** [11 December 2023 14:34 UTC](https://discourse.nodered.org/t/making-connection-secure-https-in-windows/83601 "2023-12-11T14:34:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![BitEater](https://avatars.discourse-cdn.com/v4/letter/b/dc4da7/32.png) [@BitEater](https://discourse.nodered.org/u/BitEater)\
**Post date:** [11 December 2023 14:34 UTC](https://discourse.nodered.org/t/making-connection-secure-https-in-windows/83601/1 "2023-12-11T14:34:41Z")

</div>

I am running Node Red in a Windows VM. It is only used for connection from local network. Also already added user authentication with the node-red-contrib-users node.  
But now I want to implement some browser notifications and thus it seems I have to enable HTTPS access. I found some tutorial about this but they all refer to Pi/Ubuntu. Are there any tutorials for enabling this on a Windows machine? Will this also work for a local-only use (with access via IP, without domain)?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [11 December 2023 21:12 UTC](https://discourse.nodered.org/t/making-connection-secure-https-in-windows/83601/2 "2023-12-11T21:12:23Z")

</div>

> [@BitEater](#):
>
> I want to implement some browser notifications and thus it seems I have to enable HTTPS access

More and more common to require this for all sorts of reasons. And if using any kind of web service, even over a local network, it is best to use TLS.

> [@BitEater](#):
>
> Are there any tutorials for enabling this on a Windows machine?

Probably not, not a common scenario to be honest. Even Windows people generally run microservice architectures on Linux if they can. 🙂

But if relying only on Node-RED's built-in web server, the process is the same as for Linux (the joys of working with something like Node.js) other than the locations of your 2 certificate/key files will be different. They need to be somewhere read-only to Node-RED. Node-RED should not be able to change them.

> [@BitEater](#):
>
> Will this also work for a local-only use (with access via IP, without domain)?

Not with any kind of validated TLS certificate, only self-signed since you cannot have a publicly valid certificate issued against an IP address. Self-signed certificates are a pain to work with these days I'm afraid as all browsers will complain about them unless you go to the trouble of creating a self-signed trusted root certificate as well (from which your actual cert is derived) and uploading it to all devices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [9 February 2024 21:12 UTC](https://discourse.nodered.org/t/making-connection-secure-https-in-windows/83601/3 "2024-02-09T21:12:50Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
