From b31115283bb424d714f4d1e514d261b4a1b8ed71 Mon Sep 17 00:00:00 2001
From: AsunaYukky <83214353+AsunaYukky@users.noreply.github.com>
Date: Mon, 26 Feb 2024 15:46:47 +1100
Subject: [PATCH] Created How to create self-signed SSL certificate for 3X-UI
webpanel (also if you don't use domains) (markdown)
---
...ebpanel-(also-if-you-don't-use-domains).md | 30 +++++++++++++++++++
1 file changed, 30 insertions(+)
create mode 100644 How-to-create-self‐signed-SSL-certificate-for-3X‐UI-webpanel-(also-if-you-don't-use-domains).md
diff --git a/How-to-create-self‐signed-SSL-certificate-for-3X‐UI-webpanel-(also-if-you-don't-use-domains).md b/How-to-create-self‐signed-SSL-certificate-for-3X‐UI-webpanel-(also-if-you-don't-use-domains).md
new file mode 100644
index 0000000..e7d3ee9
--- /dev/null
+++ b/How-to-create-self‐signed-SSL-certificate-for-3X‐UI-webpanel-(also-if-you-don't-use-domains).md
@@ -0,0 +1,30 @@
+## Hi team!
+### From version 2.2 3X-UI make warning for me, that I am not use TLS when I communicate with WebPanel.
+I know, that it is security issue for me, but I can't use LetsEncrypt certificate, cause I am not use domains.
+Solution - make self-signed certificate for my IP address.
+## Lets do this!
+Go to server bash.
+I create folder inside /usr/local/x-ui/ directory for cert's.
+`cd /usr/local/x-ui`
+`mkdir ssl-srt`
+`cd ssl-srt`
+Next step - create certificates. I make it for 10 years, if you need more or less - just change -days option.
+`openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -sha256 -days 3650`
+### **WARN**
+It will ask you for PEM pass phrase - remember it! It will bee needed for next step! Or use easy - I use "1234"
+
+Next step - input data for certificate. I leave all blank.
+**!!!BUT!!!**
+You need to input **your real IP address into Common Name field**.
+
+Certs made. But if you try to install it inside the panel, you will take an error, cause your private key locked by pass phrase.
+Let's unlock it!
+`openssl rsa -in key.pem -out key.un.pem -passin pass:YOUR PASS PHRASE`
+
+## And the final round - install it into the WebPanel.
+
+
+## Final
+After save and reboot Webpanel you will take an error about self-signed certificate, just ignore it. But, you will not see TLS error inside - your connection will be encrypted!
+All complete!
+Good Luck!