SSL/TLS
SSL/TLS Support​
To be able to access the the node from external source on the same network you will need to install the generated self-signed certificate.
NOTE: Installing the SSL certificate is only necessary if you plan to access the node from an external source on the same network. If you are running the application locally, you do not need to install the certificate.
Steps to Add the Certificate to Your Device​
-
Locate the Certificate:
- Download the certificate from
http://localhost:<server-port>/admin-api/certificate
. - The
<server-port>
is the port number used as an argument in the--server-port
flag in the section Initialize and start your node (separate terminal). - For example:
bash http://localhost:2428/admin-api/certificate
- Download the certificate from
-
Add the Certificate to Trusted Certificates:
-
For Windows:
- Open the
Run
dialog (Win + R) and typemmc
to open the Microsoft Management Console. - Go to
File
->Add/Remove Snap-in...
. - Select
Certificates
and clickAdd
. - Choose
Computer account
, thenNext
andFinish
. - Expand
Certificates (Local Computer)
->Trusted Root Certification Authorities
. - Right-click
Certificates
, thenAll Tasks
->Import...
. - Follow the prompts to import the certificate file.
- Open the
-
For macOS:
- Double-click the certificate file.
- This will open the
Keychain Access
application. - Choose
System
from the list of keychains. - Drag and drop the certificate into the
System
keychain. - Authenticate with your administrator password if prompted.
- Right-click the certificate and select
Get Info
. - Expand the
Trust
section and selectAlways Trust
from theWhen using this certificate
dropdown.
-
For Linux:
- Copy the certificate to
/usr/local/share/ca-certificates/
(or/etc/pki/ca-trust/source/anchors/
depending on your distribution). - Run
sudo update-ca-certificates
(orsudo update-ca-trust extract
for Red Hat-based distributions).
- Copy the certificate to
-
-
Restart Your Browser:
- Close and reopen your web browser to ensure it recognizes the newly added certificate.
Rules for Generating SSL Certificates​
- If a certificate doesn't exist, a new one will be generated based on your current local IP address.
- If a certificate exists for the current IP address, it will be used.
- If a certificate exists but is not configured for the current IP address, a new certificate will be created.
NOTE: Every time a new certificate is generated (e.g., on the first start of the server or when the IP address changes), you will need to add it to your device's trusted certificates.
Was this page helpful?