# \[Self-hosted Mender 1.7\] Non-SSL API-Gateway

**URL:** <https://hub.mender.io/t/self-hosted-mender-1-7-non-ssl-api-gateway/241>\
**Category:** General Discussions\
**Created:** [February 19, 2019, 10:45pm UTC](https://hub.mender.io/t/self-hosted-mender-1-7-non-ssl-api-gateway/241 "2019-02-19T22:45:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sabjorn](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@sabjorn](https://hub.mender.io/u/sabjorn)\
**Post date:** [February 19, 2019, 10:45pm UTC](https://hub.mender.io/t/self-hosted-mender-1-7-non-ssl-api-gateway/241/1 "2019-02-19T22:45:32Z")

</div>

I’m working on an OpenShift deployment of Mender. The cluster we’re using has certs which can be supplied automatically by the OpenShift routes. And, importantly, the private parts of those certs cannot be placed in the Mender application.

Is it possible to run the API Gateway in non-ssl mode?

---

<div class="post-metadata">

**Author:** ![erikhh](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/erikhh/32/102_2.png) [@erikhh](https://hub.mender.io/u/erikhh)\
**Post date:** [February 20, 2019, 8:04am UTC](https://hub.mender.io/t/self-hosted-mender-1-7-non-ssl-api-gateway/241/2 "2019-02-20T08:04:24Z")

</div>

I had slightly similar when I was setting up Mender in ECS. Everything is behind loadbalancers that already handle SSL.  
I solved it by adding [Certbot](https://certbot.eff.org/) to the API gateway Dockerimage. I let Certbot manage the local certificates on the API gateway instances automaticaly.

I extended the original Docker image with an entrypoint script that wraps the original entrypoint script to setup certbot before starting Nginx.

But in any case the nginx config for the API gateway is kept here: [https://github.com/mendersoftware/mender-api-gateway-docker/blob/master/nginx.conf](https://github.com/mendersoftware/mender-api-gateway-docker/blob/master/nginx.conf) You can make an extended Dockerfile that uses your own. Or use a volume to put your own in place.

---

<div class="post-metadata">

**Author:** ![sabjorn](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@sabjorn](https://hub.mender.io/u/sabjorn)\
**Post date:** [February 20, 2019, 5:57pm UTC](https://hub.mender.io/t/self-hosted-mender-1-7-non-ssl-api-gateway/241/3 "2019-02-20T17:57:03Z")

</div>

excellent! thanks for the info! You may have just saved me a lot of heartache.

Follow up question: if using CA backed certs, does the client still need local copies of the public portion (i.e. `server.crt`)?

---

<div class="post-metadata">

**Author:** ![erikhh](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/erikhh/32/102_2.png) [@erikhh](https://hub.mender.io/u/erikhh)\
**Post date:** [February 21, 2019, 7:12am UTC](https://hub.mender.io/t/self-hosted-mender-1-7-non-ssl-api-gateway/241/4 "2019-02-21T07:12:21Z")

</div>

You mena the mender client on the device? You only need to install the `server.crt` on the device when working with self-signed certificates on the backend. When you use certificates that are backed by a public certificate authority you only need to make sure the [ca-certificates](https://layers.openembedded.org/layerindex/recipe/89707/) package is installed on the device.
