Running SDK local service with HTTPS protocol

Installation settings

  1. Run Regula Downloads manager and download the required software version. Further on in this example we will be using a service version for x86 systems.
  2. During the installation you can select a required port and protocol to be used by the local service.

     

Setting up HTTPS for localhost.

The following steps are required:
  1. Install OpenSSL.
  2. Run (as administrator) start.bat from the folder that you installed OpenSSL to.
     
  3. Generate RSA-2048 key and save it as a rootCA.key file. This file will be used for created a root SSL-certificate. You will be prompted to enter a password that will be required every time you use this keyfor a certificate creation.
    To do this, enter the following command:

    openssl genrsa -des3 -out rootCA.key 2048


  4. Create a root certificate using the key generated in the previous step. You will also be prompted to enter other information (your country code, organization name, etc.).

    openssl req -x509 -new -nodes -key rootCA.key -sha256 -days 1024 -out rootCA.pem


  5. To make the certificate trusted, press Win + R and run the certmgr.msc. Open Trusted Root Certification Authorities → right-click the Certificates subfolder → All Tasks → Import and follow the instructions. Optionally, you can also add the root certificate to your browser's trusted certificates list.
  6. To create the certificate in the PFX format required for use in IIS, run the following command:

    openssl pkcs12 -export -out server.pfx -inkey rootCA.key -in rootCA.pem
  7. Import the resulting PFX file to IIS Management. If IIS Management is not installed, install it through Windows componentsWindows.
  8. Run IIS.
  9. Double click Server Certificates
  10. In the right-hand pane, click Import.
  11. Locate the certificate you created earlier in the pfx.
  12. Double-click the certificate to open its properties. Select the Thumbprint value and copy it.
  13. Now that the certificate is created, it is time to bind it to the port you are using. In this example, we will use https://localhost:443:
  14. Open Command Prompt as Administrator.
  15. Run the following command to bind the created certificate to the port in use:

    netsh http add sslcert ipport=0.0.0.0:443 certhash=[cert-thumbprint] appid={[App-Id]}

    Replace [Cert-thumbprint] (including the square brackets) with the copied value. Replace [app-id] (including the square brackets) with the GUID from the application assembly information

  16. In the settings (located in the .env file in the root installation folder)  set the HTTPS protocol and port 443.
     
  17. Run the service as Administrator.
  18. Wait for the service to start and verify that it is available at https://localhost:443 It should open without security errors. If the service does not start, check whether port 443 is already used by another service, e.g. the face comparison service. If during installation/setup you specified a port other than 443 use it 
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.

Articles in this section

See more