# Self Signed Certificate in Certificate Chain when upload data to Postgresql cloud database

**URL:** <https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640>\
**Category:** General\
**Created:** [12 August 2021 06:08 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640 "2021-08-12T06:08:21Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bond](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@Bond](https://discourse.nodered.org/u/Bond)\
**Post date:** [12 August 2021 06:08 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640/1 "2021-08-12T06:08:22Z")

</div>

Hi all,  
I was playing around with Postgresql on my local network and everything went very well. Until I change the database to a cloud server, I receive the error: "Self Signed Certificate in Certificate Chain". I assume this is because the SSL is now true.

I have the certificate provided from the cloud server look like this:  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/7/7722cf3fb55eece68ef15da126f37800ea27550a.png)

Here is my very simple flow just to upload first data to the database:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/8/38aec0c197aecf928173d4902dade802022e4081.png)

So, how do I fix this error? Where can I insert my CA-certificate into the flow? Sorry, I'm completely new to networking and security functions.  
I found some people suggesting disabling the authorization, but to keep the data safe, it is clearly not an ideal solution, right?

Also, I am using the: `node-red-contrib-postgrestor-next`  
Node-red version: `v2.0.5`  
Node.js version: `v14.17.4`

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 August 2021 14:49 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640/2 "2021-08-12T14:49:37Z")

</div>

So when a certificate is created, it has a cascade of trust from a "Root Certificate Authority" or RootCA. Each step of the chain of certificates is "signed" by the parent. In this way you get a trusted certificate chain.

Now, if you create your own certificates locally using OpenSSL, you are using a "self-signed" certificate because you don't have a real RootCA.

So if you try and use such a certificate with a public service, the service will try to validate the chain because otherwise it cannot trust the certificate. With a self-signed cert, it cannot do this because it doesn't know about your pseudo-root.

There are various approaches to fixing this issue:

- Get the service to ignore the error - really not a good idea because someone else could now pretend to be you.
- Give the service a root CA to trust - while this works ok with local browsers, it generally won't be possible on cloud services unless you own the underlying infrastructure.
- Get a "proper" certificate that has been signed by a RootCA that is widely recognised.

This last one is really the only viable choice. There are now several free services that will give you a certificate like this. However, most people are now using Let's Encrypt. There are a number of older threads in the forum that talk about LE and how to get Node-RED set up using LE certs and that may give you the clues you need to get your requirements working.

---

<div class="post-metadata">

**Author:** ![Bond](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@Bond](https://discourse.nodered.org/u/Bond)\
**Post date:** [12 August 2021 15:35 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640/3 "2021-08-12T15:35:43Z")

</div>

Thank you for your reply, I learn something now.

Just to be specific, I am using Postgresql database on Digitalocean, which provided a RootCA to be downloaded.  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/0/2/027ca923000c2eb716cefa3a4fcdfc0ae158e0d4.png)

I just don't know how to insert that certificate into Nodered. I'll look into old threads in the forum about LE, maybe I can get some ideal out of them.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 August 2021 16:09 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640/4 "2021-08-12T16:09:19Z")

</div>

Ah, OK so the other way around to what I was describing. Same principles except that you probably DO have control over your Node-RED server.

What platform are you using to run Node-RED?

---

<div class="post-metadata">

**Author:** ![Bond](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@Bond](https://discourse.nodered.org/u/Bond)\
**Post date:** [12 August 2021 23:56 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640/5 "2021-08-12T23:56:23Z")

</div>

It is running on Raspberry Pi, `Linux 5.10.52-v7+ arm LE`

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [13 August 2021 06:51 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640/6 "2021-08-13T06:51:12Z")

</div>

[node-red-contrib-digitaloak-postgresql (node) - Node-RED](https://flows.nodered.org/node/@digitaloak/node-red-contrib-digitaloak-postgresql) supports TLS - have you tried this node?

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/9/b959bd30ecc43f9f7f96ba28f76da5725b1ff10d.png)

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/9/b959bd30ecc43f9f7f96ba28f76da5725b1ff10d.png)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [14 August 2021 01:38 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640/7 "2021-08-14T01:38:42Z")

</div>

OK, so it is possible to load external custom root CA's into Linux. You would need to look it up.

But do try Steve's suggestion first as that is probably all you need.

---

<div class="post-metadata">

**Author:** ![Bond](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@Bond](https://discourse.nodered.org/u/Bond)\
**Post date:** [15 August 2021 11:55 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640/8 "2021-08-15T11:55:37Z")

</div>

Thank you for the reply. After learning some TLS configuration, and trying `@digitaloak/node-red-contrib-digitaloak-postgresql`  
I still have errors with authentication.  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/6/a69ab39c7bec1b1eef81a2d7566116e1d64b576d.png)

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/3/b3f666047e8b55c996f6a561f8d490bcad5c2c55.png)  
I uploaded the CA Certification  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/b/cb1e44d1f66b49a173feb6cc68160dbabf34f780.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [14 October 2021 11:56 UTC](https://discourse.nodered.org/t/self-signed-certificate-in-certificate-chain-when-upload-data-to-postgresql-cloud-database/49640/9 "2021-10-14T11:56:05Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
