# Adding SSL to genieACS

**URL:** <https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445>\
**Category:** Uncategorized\
**Created:** [February 21, 2022, 8:57am UTC](https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445 "2022-02-21T08:57:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![saymosthasfar](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/saymosthasfar/32/802_2.png) [@saymosthasfar](https://forum.genieacs.com/u/saymosthasfar)\
**Post date:** [February 21, 2022, 8:57am UTC](https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445/1 "2022-02-21T08:57:36Z")

</div>

Hello all  
I’m using GenieACS v1.2.8 and trying to add SSL to it according to this manual  
[GenieACS SSL](https://github.com/genieacs/genieacs/wiki/GenieACS-SSL)  
but it seems this wiki page is outdated since there is no config file in v1.2 and higher. The question is that where should I store .cert and .key files and where to add e.g. CWMP\_SSL entry?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![webtron](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/webtron/32/396_2.png) [@webtron](https://forum.genieacs.com/u/webtron)\
**Post date:** [February 22, 2022, 9:43pm UTC](https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445/2 "2022-02-22T21:43:18Z")

</div>

This should probably go in the wiki

> [@1.2.3 Let's encrypt https ui without Nginx or Apache2](https://forum.genieacs.com/t/1-2-3-lets-encrypt-https-ui-without-nginx-or-apache2/1379):
>
> I couldn’t find any laid out instructions for this and it’s missing from the install instructions so I thought I’d share. This is without using Nginx or Apache2 so it was harder to find info on setting it up and I want the certs to renew automatically. If you have nothing else running on port 80 you can run certbot in “standalone” mode. In standalone mode certbot will listen itself on port 80 for the authourization. Make sure you have your domain name pointing at your servers IP sudo apt up…

---

<div class="post-metadata">

**Author:** ![hrc91](https://avatars.discourse-cdn.com/v4/letter/h/9e8a1a/32.png) [@hrc91](https://forum.genieacs.com/u/hrc91)\
**Post date:** [May 19, 2022, 8:00am UTC](https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445/3 "2022-05-19T08:00:06Z")

</div>

> [@1.2.3 Let's encrypt https ui without Nginx or Apache2](https://forum.genieacs.com/t/1-2-3-lets-encrypt-https-ui-without-nginx-or-apache2/1379/1):
>
> the /opt/genieacs/genieacs.env and add these 2 lines

Thank you so much for the prompt response.  
These are only guidelines for making HTTPS on GenieACS UI, not between GenieACS and CPE.  
What we want is HTTPS between CPE and ACS.  
Thanks~~

---

<div class="post-metadata">

**Author:** ![JonasGhost](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/jonasghost/32/286_2.png) [@JonasGhost](https://forum.genieacs.com/u/JonasGhost)\
**Post date:** [May 19, 2022, 8:33am UTC](https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445/4 "2022-05-19T08:33:37Z")

</div>

Exchange the variable/env names and you have HTTPS for CWMP/FS and NBI

---

<div class="post-metadata">

**Author:** ![hrc91](https://avatars.discourse-cdn.com/v4/letter/h/9e8a1a/32.png) [@hrc91](https://forum.genieacs.com/u/hrc91)\
**Post date:** [May 19, 2022, 8:59am UTC](https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445/5 "2022-05-19T08:59:14Z")

</div>

Hi Jonas,  
Would you describe more clearly?

---

<div class="post-metadata">

**Author:** ![JonasGhost](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/jonasghost/32/286_2.png) [@JonasGhost](https://forum.genieacs.com/u/JonasGhost)\
**Post date:** [May 19, 2022, 9:17am UTC](https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445/6 "2022-05-19T09:17:27Z")

</div>

Have a look at this: [Environment Variables — GenieACS Documentation 1.2.8 documentation](http://docs.genieacs.com/en/latest/environment-variables.html)  
These are the ENVs you need.  
GENIEACS\_CWMP\_SSL\_CERT  
GENIEACS\_CWMP\_SSL\_KEY  
GENIEACS\_NBI\_SSL\_KEY  
GENIEACS\_NBI\_LOG\_FILE  
GENIEACS\_FS\_SSL\_CERT  
GENIEACS\_FS\_SSL\_KEY

These work like the variable described here:  
GENIEACS\_UI\_SSL\_CERT=/etc/letsencrypt/live/MyDomainExample.com/fullchain.pem  
GENIEACS\_UI\_SSL\_KEY=/etc/letsencrypt/live/MyDomainExample.com/privkey.pem  
( [1.2.3 Let's encrypt https ui without Nginx or Apache2](https://forum.genieacs.com/t/1-2-3-lets-encrypt-https-ui-without-nginx-or-apache2/1379) )  
It is also possible / recommended to use different domains for the different services. This allows to split them when needed in the furture.

---

<div class="post-metadata">

**Author:** ![hrc91](https://avatars.discourse-cdn.com/v4/letter/h/9e8a1a/32.png) [@hrc91](https://forum.genieacs.com/u/hrc91)\
**Post date:** [May 19, 2022, 10:22am UTC](https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445/7 "2022-05-19T10:22:35Z")

</div>

Hi Jonas,  
Thanks for your response.  
I tried adding 2 below variables to the genieacs.env file.  
GENIEACS\_CWMP\_SSL\_CERT=/opt/genieacs/ext/cwmp.crt  
GENIEACS\_CWMP\_SSL\_KEY=/opt/genieacs/ext/cwmp.key

And tried to connect the CPE with an HTTPS connection.  
Unfortunately, it did not work.  
FYI: it worked with GenieACS version 1.0.

---

<div class="post-metadata">

**Author:** ![hrc91](https://avatars.discourse-cdn.com/v4/letter/h/9e8a1a/32.png) [@hrc91](https://forum.genieacs.com/u/hrc91)\
**Post date:** [May 23, 2022, 8:34am UTC](https://forum.genieacs.com/t/adding-ssl-to-genieacs/2445/8 "2022-05-23T08:34:18Z")

</div>

Hello Jonas,  
After changing the cert and key file, it worked. My bad!  
Thanks for your support!!!

sudo chown genieacs /opt/genieacs/cwmp.crt  
sudo chown genieacs /opt/genieacs/cwmp.key

Add 2 below lines into genieacs.env file:  
GENIEACS\_CWMP\_SSL\_CERT=/opt/genieacs/cwmp.crt  
GENIEACS\_CWMP\_SSL\_KEY=/opt/genieacs/cwmp.key
