Hub https

Pecbeck
Established Contributor
Established Contributor

Does anyone know why the hub requires switching to https,  but then reverts to http. Why does it not have an ssl certificate if it insists on https? 

5 REPLIES 5
bobpullen
Ace Contributor
Ace Contributor

Where are you seeing it revert to http? I get the initial redirect/browser override and from there it all looks to be https.

The hub does have a TLS certificate but it's self-signed (thus the browser errors). In theory, there's no reason why it couldn't use a 'proper', publicly-signed certificate but I imagine it would involve either offering the funcitonality for customers to generate and upload their own certs to the hub (can't see that happening), or some sort of management process that silently generates/renews/installs certificates as required for each customer's hub - not impossible, but probably complex/costly.

Pecbeck
Established Contributor
Established Contributor

When i browse the hub, I get the use https dialogue then the standard dialogues about safety, and proceed anyway. When it the opens the hub web page the https:// is in red, meaning it is not a secure ssl connection

That is what I meant by it reverts to http, basically insecure. There appears to be no certificate, hence my question

So what is the point of forcing the browser to https, only to say its invalid?

tnj
Skilled Contributor
Skilled Contributor

It shows red as it sees the certificate as invalid, it is still https protocol.

Pecbeck
Established Contributor
Established Contributor

Yes you are right. Wonder if I can somehow create a cert. 

I have configured my laptop to correctly verify the SSL certificate used by my new EE Hub. It appears to use a certificate issued by BT Hub Root  CA which is not a public CA.  View the certificate details in the browser and you can see the certificate hierarchy.  Select the root CA certificate and Export it to a .crt file. If you then import the certificate into the trusted root certificate store using the settings security options the certificate can be verified.   However, you may see a different error regarding the certificate common name if you do not use the https://bthomehub.home address.  This can fixed by editing the hosts file and adding 192.168.1.254 bthomehub.home to the file.  Hope this helps.