Skip to main content

HTTPS for Station

Station serves plain HTTP on port 8000 out of the box, which is fine for a lab but not for operators' browsers on a real network. HTTPS also unlocks the features that use the browser's camera: browsers only grant camera access to secure origins, so the live capture on the Identify a face page and photo capture when registering a watchlist member or working in the event history need HTTPS (or the Chrome exception at the end of this page). The REST and GraphQL APIs stay on HTTP behind Station; to expose them securely put a reverse proxy in front, see Authentication.

Enable HTTPS in Station​

Station reads its TLS settings from .env.station:

KeyMeaning
HTTPS_ENABLEDtrue to serve HTTPS on the Station port.
HTTPS_HOST_NAMEThe host name operators type in the browser; it must match a name in the certificate.
HTTPS_KEY_FILEPath to the private key inside the container.
HTTPS_CERT_FILEPath to the certificate (with any intermediate certificates appended) inside the container.
  1. Put the key and certificate in a certs/ folder next to docker-compose.yml and mount them into the Station container by adding to docker-compose.override.yml:

    services:
    station:
    volumes:
    - ./certs/station.key:/certs/station.key:ro
    - ./certs/station.crt:/certs/station.crt:ro
  2. Set the keys in .env.station:

    HTTPS_ENABLED=true
    HTTPS_HOST_NAME=station.example.com
    HTTPS_KEY_FILE=/certs/station.key
    HTTPS_CERT_FILE=/certs/station.crt
  3. Turn on the browser camera if you want it: DOT_FACE_CAMERA_ENABLED=true in the same file.

  4. Apply with docker compose up -d station and open https://station.example.com:8000.

For production, use a certificate for that host name from your organisation's certificate authority (CA) or a public CA; every operator's browser trusts it without further steps. The sections below are for test and pilot systems without such a CA.

Generate a local CA and a Station certificate​

Create a private CA once, then sign a certificate for the Station host name with it. Run on any Linux or macOS machine with OpenSSL:

mkdir -p ~/certs && cd ~/certs
# 1. Local CA: private key and root certificate (valid 5 years)
openssl genrsa -des3 -out myCA.key 2048
openssl req -x509 -new -nodes -key myCA.key -sha256 -days 1825 -out myCA.pem

# 2. Station key and certificate signing request
openssl genrsa -out station.key 2048
openssl req -new -key station.key -out station.csr

# 3. Extension file with the Subject Alternative Name browsers require
cat > station.ext <<'EOF'
authorityKeyIdentifier=keyid,issuer
basicConstraints=CA:FALSE
keyUsage = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment
subjectAltName = @alt_names
[alt_names]
DNS.1 = station.example.com
EOF

# 4. Sign the request with the CA (valid 825 days)
openssl x509 -req -in station.csr -CA myCA.pem -CAkey myCA.key -CAcreateserial \
-out station.crt -days 825 -sha256 -extfile station.ext

Copy station.key and station.crt to the certs/ folder on the Face Matcher host and enable HTTPS as above. Keep myCA.key private; anyone holding it can issue certificates your browsers will trust. Add DNS.2 = ... or IP.1 = 192.168.0.100 lines if operators use another name or the IP address.

Trust the local CA in browsers​

Import myCA.pem as a trusted root on every operator workstation; the Station certificate is then trusted automatically.

  • macOS: sudo security add-trusted-cert -d -r trustRoot -k "/Library/Keychains/System.keychain" myCA.pem
  • Windows: open certlm.msc, go to Trusted Root Certification Authorities > Certificates, right-click, All Tasks > Import, choose myCA.pem (set the file filter to All Files) and keep the default store.
  • Linux (Ubuntu): sudo cp myCA.pem /usr/local/share/ca-certificates/myCA.crt && sudo update-ca-certificates. Chrome and Firefox keep their own stores: add the CA under Settings > Privacy and security > Security > Manage certificates > Authorities.
  • Mobile devices can import the same file through their certificate settings; the steps vary by platform and version.

Restart the browser and confirm the padlock shows on https://station.example.com:8000.

Test-only alternative: trust the HTTP origin in Chrome​

For a quick lab test of the camera features without certificates, Chrome can treat one plain-HTTP origin as secure. Open chrome://flags/#unsafely-treat-insecure-origin-as-secure, add the Station URL including the port (for example http://192.168.0.100:8000), set the flag to Enabled and relaunch. With DOT_FACE_CAMERA_ENABLED=true the camera preview then appears on the identification page. This applies to one browser on one machine and weakens its security; never use it in production.