SSL Certificates
4 min
SSL Certificates
Litmus Edge ships with a self-signed certificate. Until you install your own CA, clients will reject the connection.
Quick fix (development only)
Disable certificate verification on the client:
Tool | Flag |
|---|---|
cURL | -k or --insecure |
Python requests | verify=False |
Postman | Settings -> General -> "SSL certificate verification" off |
Node https / fetch | rejectUnauthorized: false |
curl -k "https://<edge-host>/devicehub/version" -H "Authorization: Bearer $TOKEN"Never do this against production traffic. It opens you to MITM.
Production fix
Install a CA-signed certificate on the edge:
- System -> Network -> Certificates -> Upload Custom Certificate
- Or use the Upload Custom CA Certificate workflow: see Upload Custom CA Certificate (LE)
Once installed, drop -k / verify=False from your clients.
Trusting the edge's self-signed cert
If you don't want a public CA cert but still want clients to validate, export the edge's self-signed cert and add it to your client's trust store:
echo | openssl s_client -connect <edge-host>:443 -servername <edge-host> 2>/dev/null \
| openssl x509 > edge.crt
# Python
export REQUESTS_CA_BUNDLE=$(pwd)/edge.crt
# curl
curl --cacert edge.crt "https://<edge-host>/devicehub/version" ...