# Node-RED SSL using Letsencrypt & Certbot

**URL:** <https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606>\
**Category:** Share Your Projects\
**Tags:** security\
**Created:** [6 November 2019 20:22 UTC](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606 "2019-11-06T20:22:22Z")\
**Posts on this page:** 1\
**Showing post:** 36

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [23 May 2020 14:39 UTC](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606/36 "2020-05-23T14:39:56Z")

</div>

> [@Roaders](#):
>
> Out of interest why do you copy the certificates to a different folder rather than just using them where they are generated?

Node-RED normally runs as a 'user', and Letsencrypt creates the certificates in `etc/letsencrypt/live/` with root ownership, and therefore without changing the ownership of the certificates to `pi`, node\_RED would not be able to read them.

So... rather than start altering files that sit within the Letsencrypt directory, I prefer to copy the certificates to the node-RED user directory and then use chown to make them readable (it's all done by the script).  
That then keeps the two services independent, and for me has the advantage that when I back-up node-RED, it also backs up the node-RED certificates in the NR user dir. If I ever needed to quickly restore the backup, I could be back online, complete with https in minutes without having to worry about Letsencrypt/Certbot.

---

_[View the full topic](https://discourse.nodered.org/t/node-red-ssl-using-letsencrypt-certbot/17606)._
