diff --git a/How-to-create-self‐signed-SSL-certificate-for-3X‐UI-webpanel-(also-if-you-don't-use-domains).md b/How-to-create-self‐signed-SSL-certificate-for-3X‐UI-webpanel-(also-if-you-don't-use-domains).md new file mode 100644 index 0000000..e7d3ee9 --- /dev/null +++ b/How-to-create-self‐signed-SSL-certificate-for-3X‐UI-webpanel-(also-if-you-don't-use-domains).md @@ -0,0 +1,30 @@ +## Hi team!
+### From version 2.2 3X-UI make warning for me, that I am not use TLS when I communicate with WebPanel.
+I know, that it is security issue for me, but I can't use LetsEncrypt certificate, cause I am not use domains.
+Solution - make self-signed certificate for my IP address.
+## Lets do this!
+Go to server bash.
+I create folder inside /usr/local/x-ui/ directory for cert's.
+`cd /usr/local/x-ui`
+`mkdir ssl-srt`
+`cd ssl-srt`
+Next step - create certificates. I make it for 10 years, if you need more or less - just change -days option.
+`openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -sha256 -days 3650`
+### **WARN**
+It will ask you for PEM pass phrase - remember it! It will bee needed for next step! Or use easy - I use "1234"
+![1](https://github.com/MHSanaei/3x-ui/assets/83214353/7dec3195-4eaa-4ea8-a486-e1b4ca2115a5)
+Next step - input data for certificate. I leave all blank.
+**!!!BUT!!!**
+You need to input **your real IP address into Common Name field**.
+![2](https://github.com/MHSanaei/3x-ui/assets/83214353/7dcb0a8c-6599-44a8-80d7-e6e35e4c827f)
+Certs made. But if you try to install it inside the panel, you will take an error, cause your private key locked by pass phrase.
+Let's unlock it!
+`openssl rsa -in key.pem -out key.un.pem -passin pass:YOUR PASS PHRASE`
+![image](https://github.com/MHSanaei/3x-ui/assets/83214353/bd8609f5-7ac1-4831-ac36-b32e46f8a282)
+## And the final round - install it into the WebPanel.
+![image](https://github.com/MHSanaei/3x-ui/assets/83214353/5268e88a-d7fa-4429-93ba-f07ea3958ca4) + +## Final +After save and reboot Webpanel you will take an error about self-signed certificate, just ignore it. But, you will not see TLS error inside - your connection will be encrypted!
+All complete!
+Good Luck!