# Configure FS with SSL

**URL:** <https://forum.genieacs.com/t/configure-fs-with-ssl/321>\
**Category:** Uncategorized\
**Created:** [October 1, 2019, 8:37am UTC](https://forum.genieacs.com/t/configure-fs-with-ssl/321 "2019-10-01T08:37:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chmutoff](https://avatars.discourse-cdn.com/v4/letter/c/74df32/32.png) [@chmutoff](https://forum.genieacs.com/u/chmutoff)\
**Post date:** [October 1, 2019, 8:37am UTC](https://forum.genieacs.com/t/configure-fs-with-ssl/321/1 "2019-10-01T08:37:08Z")

</div>

Hello.

I’m using the 1.2beta version (from master). I have nginx installed as a proxy for GenieACS services. When I request a file with https the nginx gives it back with no poblem, so it is configured and ready to receive requests. The problme is when I try to push a file from GUI or provision script, it always requests it with http and nginx returns a 400 error. I have tried using the FS\_SSL=true (which is not in the new docs). I have used the SSL\_CERT for all the services (cwmp, ui, fs, nbi) but the request is still going throuh http instead of https.

Can you please help me? What am I doing wrong?

Regards

---

<div class="post-metadata">

**Author:** ![arvydas](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@arvydas](https://forum.genieacs.com/u/arvydas)\
**Post date:** [December 19, 2019, 11:07am UTC](https://forum.genieacs.com/t/configure-fs-with-ssl/321/2 "2019-12-19T11:07:02Z")

</div>

Hi,

I seem to have the same problem (no NGINX, directly from genieacs-fs service). Maybe you have found a solution already?

Regards  
Arvydas

---

<div class="post-metadata">

**Author:** ![chmutoff](https://avatars.discourse-cdn.com/v4/letter/c/74df32/32.png) [@chmutoff](https://forum.genieacs.com/u/chmutoff)\
**Post date:** [December 19, 2019, 5:32pm UTC](https://forum.genieacs.com/t/configure-fs-with-ssl/321/3 "2019-12-19T17:32:32Z")

</div>

Hi. At the moment I left it without SSL, but I remembeer seen something about this in one of the latest Git changes in master. You could try that.

---

<div class="post-metadata">

**Author:** ![LuKePicci](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.genieacs.com/lukepicci/32/171_2.png) [@LuKePicci](https://forum.genieacs.com/u/LuKePicci)\
**Post date:** [January 21, 2020, 11:50am UTC](https://forum.genieacs.com/t/configure-fs-with-ssl/321/4 "2020-01-21T11:50:16Z")

</div>

This is crucial to avoid dns hijacking on firmwares/vcfs being pushed.

The root cause of this is the way genieacs determines the FS endpoint URL.

We would need the ability to setup TLS/port of FS server independently from what genieacs uses as FS endpoint in download tasks.

I deployed this on Azure App Service and everything must be behind a single port, so having a proxy\_pass nginx was the obvious solution. Everything runs on their default ports with no TSL, App Service is taking care of TLS, nginx is passing CWMP requests to genieacs-cwmp, file requests to genieacs-fs, everything else to genieacs ui.

I needed a genieacs config to setup the right URL for FS requests:. FS\_URL\_PREFIX  
In my case such a config is set to “[https://myappservice.azurewebsites.net/files/](https://myappservice.azurewebsites.net/files/)” and every download task for “[https://myappservice.azurewebsites.net/files/myvcf.xml](https://myappservice.azurewebsites.net/files/myvcf.xml)” points through proxy to http://{FS\_IP}:{FS\_PORT}
