# Setup of https/ssl - local WebXR/Quest development

**URL:** <https://discourse.nodered.org/t/setup-of-https-ssl-local-webxr-quest-development/96224>\
**Category:** Share Your Projects\
**Tags:** docker, ssl\
**Created:** [24 March 2025 18:00 UTC](https://discourse.nodered.org/t/setup-of-https-ssl-local-webxr-quest-development/96224 "2025-03-24T18:00:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gregorius](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gregorius/32/73816_2.png) [@gregorius](https://discourse.nodered.org/u/gregorius)\
**Post date:** [24 March 2025 18:00 UTC](https://discourse.nodered.org/t/setup-of-https-ssl-local-webxr-quest-development/96224/1 "2025-03-24T18:00:04Z")

</div>

Hi There,

Just wanted to share my _joy_ of setting up https on my local server using Node-RED.

I've had to setup ssl a couple times before and its always been a pain (Nginx/Apache configs, self-signing authority and/or let's encrypt with ACME endpoints ... ) and I was facing the same pains this morning when I needed SSL connection to my local machine, within my own local network. Why? Because WebXR **only** works[1] with https - _eyes rolling_.

So the scenario is that I want to render some 3D content in my Quest3 served from my local machine. To view this within the Quest, I'm using WebXR (via BabylonJS) and that requires a https source. (Up until now, I've been using a cloud server which is behind an https proxy.)

I was already dreading setting up something (aka a proxy) on a raspberry using apache or nginx .... but then I remembered that there was https support baked into Node-RED[2] ... so I thought ok, lets give it a whirl on the old FJ. Turns out it's dead simple ... once I discovered the three openssl commands from [this page](https://www.baeldung.com/openssl-self-signed-cert):

```auto
prompt> hostnme=server-name-in-my-local-dns-server
prompt> openssl genrsa -out ${hostnme}.key 2048
prompt> openssl req -key ${hostnme}.key -new -out ${hostnme}.csr
prompt> openssl x509 -signkey ${hostnme}.key -in ${hostnme}.csr -req -days 365 -out ${hostnme}.crt

```

that generates the two files that get used by Node-RED to create SSL connections, in the settings.js file:

```auto
    /** Option 1: static object */
    https: {
      key: require("fs").readFileSync('/data/server-name-in-my-local-dns-server.key'),
      cert: require("fs").readFileSync('/data/server-name-in-my-local-dns-server.crt')
    },

```

(`/data` here because this Node-RED is running in a docker image).

The ssl connection is available under the `uiPort` setting --\> `https://server-name-in-my-local-dns-server:1880/` i.e., there is no longer a http endpoint, only an ssl endpoint.

Opening that in my Quest and accepting the dangers of my own certificate (thankfully Meta didn't get rid of the "I accept the risk of using a self-signed certificate" option in the browser), e'voila, my Quest3 is now happy to render my 3D content 🙂

Big thanks to everyone involved in making https so simple 👍

[1]=strictly not, `localhost` is also possible but how do I start a server on a Quest3 to server my content - since localhost within the quest3 is the quest3 ... thanks Meta for thinking this one through!

[2]=it happens that my HTML content that renders the 3D scene is hosted in Node-RED - as a flow consisting of a bunch of template nodes

P.S: it's all been [documented](https://nodered.org/docs/user-guide/runtime/securing-node-red) already but that seems to be for Let's Encrypt certificates ...

---

<div class="post-metadata">

**Author:** ![gregorius](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gregorius/32/73816_2.png) [@gregorius](https://discourse.nodered.org/u/gregorius)\
**Post date:** [27 March 2025 11:56 UTC](https://discourse.nodered.org/t/setup-of-https-ssl-local-webxr-quest-development/96224/2 "2025-03-27T11:56:36Z")

</div>

Another learning is that the http request node won't connect to a server with a self-signed SSL certificate:

![Screenshot 2025-03-27 at 12.53.35](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/f/4f942743f4c3f2c1aa60cb9f7e8ab4891e401a8b.png)

The fix is to provide a TLS configuration:

 ![Screenshot 2025-03-27 at 12.54.11](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/6/96862d0ca73692d5055842c71cd65621acb8eb6f.png)

And in that TLS configuration the only thing to do is uncheck _Verify server certificate_ (default checked):

 ![Screenshot 2025-03-27 at 12.55.23](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/4/c40d9524157d0f1184f2235aa38da4152abab849.png)

ITE: Much ado about nothing.
