evcc.local certificate #24735
Replies: 4 comments 4 replies
|
You need a reverse proxy with nginx or apache between chrome and evcc. |
|
So esssentially, if you run a webservice via http, all data between your browser and the remote server gets transfered unencrypted. So it's up for grabs for anybody who knows how to intercept the traffic. Modern browsers encourage the use of https for obvious reasons. Some also have requirements on key length and validity period of the certificate used. So no more certificates that are valid for the next 100 years or so. The biggest risk with evcc running on your local network would be that someone could snatch your admin password and then do with it whatever he wants. But that risk is up to you to evaluate. As mentioned, for evcc (and many other self hosted network services) you‘d need a reverse proxy server (like nginx) to accept https traffic and then forward it (on a secure connection) to the http server built into your network service. This is mostly achieved by running both of them on the same system. Personally i use certbot to get me a wildward certificate from Let's Encrypt (valid for all subdomains on a given domain). The certbot server then scp's the downloaded files to a default location on all other servers on my local network. It then runs an individual script on each of these which will move the files to the proper location where the respective https server expects them and then restarts the https service (mostly the nginx service). You could to this manually but since a certificate from Let's Encrypt is only valid for 3 months that's a task you practically need to automate. If your evcc instance runs inside a docker container that adds an additional layer of complexity but not by much. |
|
Very easy, |
|
Excellent suggestion. The remote access option creates a secure connection from my laptop and remote access from my mobile device.
Thanks
Sent from [Proton Mail](https://proton.me/mail/home) for iOS.
…-------- Original Message --------
On Thursday, 08/13/26 at 22:46 StefanSchoof ***@***.***> wrote:
In 2026 there is easier way to get Remote access: https://docs.evcc.io/en/features/remote-access/
—
Reply to this email directly, [view it on GitHub](#24735?email_source=notifications&email_token=CK5SY46RG5VRHYQCPZ3B5YD5JYSMFA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBQGA3TKMRTUZZGKYLTN5XKOY3PNVWWK3TUUVSXMZLOOSWGM33PORSXEX3DNRUWG2Y#discussioncomment-18007523), or [unsubscribe](https://github.com/notifications/unsubscribe-auth/CK5SY45XGM7MSLXLOGH6FAD5JYSMFAVCNFSNUABHKJSXA33TNF2G64TZHMZDENRTGY4DGMZYHNCGS43DOVZXG2LPNY5TSMBXGE2TKMVBOYBA).
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for [iOS](https://github.com/notifications/mobile/ios/CK5SY45TC3AL7L275TXVV235JYSMFA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBQGA3TKMRTUZZGKYLTN5XKOY3PNVWWK3TUUVSXMZLOOSVGM33PORSXEX3JN5ZQ) and [Android](https://github.com/notifications/mobile/android/CK5SY4636LE5YJAWXGUZKGL5JYSMFA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBQGA3TKMRTUZZGKYLTN5XKOY3PNVWWK3TUUVSXMZLOOSXGM33PORSXEX3BNZSHE33JMQ). Download it today!
You are receiving this because you commented.Message ID: ***@***.***>
|
Uh oh!
There was an error while loading. Please reload this page.
Hello,
I have a very newbie question. What is the easiest way to have a signed certificate for evcc access on chrome, and get rid of the non-secured message?
I tried to have it working with my vague knowledge. ChatGPT sent me in a rabbit hole with mkcert and nginx, but of course it was unsuccessful.
Any tips?
All reactions