HTTPS for Station
Station serves plain HTTP on port 8000 out of the box, which is fine for a lab but not for operators' browsers on a real network. HTTPS also unlocks the features that use the browser's camera: browsers only grant camera access to secure origins, so the live capture on the Identify a face page and photo capture when registering a watchlist member or working in the event history need HTTPS (or the Chrome exception at the end of this page). The REST and GraphQL APIs stay on HTTP behind Station; to expose them securely put a reverse proxy in front, see Authentication.
Enable HTTPS in Station
Station reads its TLS settings from .env.station:
| Key | Meaning |
|---|---|
HTTPS_ENABLED | true to serve HTTPS on the Station port. |
HTTPS_HOST_NAME | The host name operators type in the browser; it must match a name in the certificate. |
HTTPS_KEY_FILE | Path to the private key inside the container. |
HTTPS_CERT_FILE | Path to the certificate (with any intermediate certificates appended) inside the container. |
-
Put the key and certificate in a
certs/folder next todocker-compose.ymland mount them into the Station container by adding todocker-compose.override.yml:services:station:volumes:- ./certs/station.key:/certs/station.key:ro- ./certs/station.crt:/certs/station.crt:ro -
Set the keys in
.env.station:HTTPS_ENABLED=trueHTTPS_HOST_NAME=station.example.comHTTPS_KEY_FILE=/certs/station.keyHTTPS_CERT_FILE=/certs/station.crt -
Turn on the browser camera if you want it:
DOT_FACE_CAMERA_ENABLED=truein the same file. -
Apply with
docker compose up -d stationand openhttps://station.example.com:8000.
For production, use a certificate for that host name from your organisation's certificate authority (CA) or a public CA; every operator's browser trusts it without further steps. The sections below are for test and pilot systems without such a CA.
Generate a local CA and a Station certificate
Create a private CA once, then sign a certificate for the Station host name with it. Run on any Linux or macOS machine with OpenSSL:
mkdir -p ~/certs && cd ~/certs
# 1. Local CA: private key and root certificate (valid 5 years)
openssl genrsa -des3 -out myCA.key 2048
openssl req -x509 -new -nodes -key myCA.key -sha256 -days 1825 -out myCA.pem
# 2. Station key and certificate signing request
openssl genrsa -out station.key 2048
openssl req -new -key station.key -out station.csr
# 3. Extension file with the Subject Alternative Name browsers require
cat > station.ext <<'EOF'
authorityKeyIdentifier=keyid,issuer
basicConstraints=CA:FALSE
keyUsage = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment
subjectAltName = @alt_names
[alt_names]
DNS.1 = station.example.com
EOF
# 4. Sign the request with the CA (valid 825 days)
openssl x509 -req -in station.csr -CA myCA.pem -CAkey myCA.key -CAcreateserial \
-out station.crt -days 825 -sha256 -extfile station.ext
Copy station.key and station.crt to the certs/ folder on the Face Matcher host and enable HTTPS as above. Keep myCA.key private; anyone holding it can issue certificates your browsers will trust. Add DNS.2 = ... or IP.1 = 192.168.0.100 lines if operators use another name or the IP address.
Trust the local CA in browsers
Import myCA.pem as a trusted root on every operator workstation; the Station certificate is then trusted automatically.
- macOS:
sudo security add-trusted-cert -d -r trustRoot -k "/Library/Keychains/System.keychain" myCA.pem - Windows: open
certlm.msc, go to Trusted Root Certification Authorities > Certificates, right-click, All Tasks > Import, choosemyCA.pem(set the file filter to All Files) and keep the default store. - Linux (Ubuntu):
sudo cp myCA.pem /usr/local/share/ca-certificates/myCA.crt && sudo update-ca-certificates. Chrome and Firefox keep their own stores: add the CA under Settings > Privacy and security > Security > Manage certificates > Authorities. - Mobile devices can import the same file through their certificate settings; the steps vary by platform and version.
Restart the browser and confirm the padlock shows on https://station.example.com:8000.
Test-only alternative: trust the HTTP origin in Chrome
For a quick lab test of the camera features without certificates, Chrome can treat one plain-HTTP origin as secure. Open chrome://flags/#unsafely-treat-insecure-origin-as-secure, add the Station URL including the port (for example http://192.168.0.100:8000), set the flag to Enabled and relaunch. With DOT_FACE_CAMERA_ENABLED=true the camera preview then appears on the identification page. This applies to one browser on one machine and weakens its security; never use it in production.