Certificates
TLS certificates in SBN Media - obtaining and renewing Let's Encrypt certificates for the encrypted SIP and HTTPS endpoints.
Certificates
SBN Media uses TLS certificates to secure its encrypted connections - the secure SIP ports, secure WebSocket, and HTTPS. It can obtain and renew these certificates automatically from Let's Encrypt.
Overview
The encrypted endpoints across SBN Media use TLS certificates: the secure SIP ports (sips and wss) on the SIP Server, and HTTPS on the API Proxy. SBN Media manages these certificates for you - it obtains a free certificate from Let's Encrypt for a domain you control, stores it, and renews it before it expires.
Certificates are stored as files - a certificate and a matching key per domain - in SBN Media's certificate directory, and the encrypted endpoints load them from there.
- Applies to: Every encrypted endpoint - secure SIP (
sips/wss) and HTTPS (the API Proxy). - Required: Only when you use encrypted connections. Plain, unencrypted endpoints do not need a certificate.
- Depends on: A domain you control that Let's Encrypt is able to verify.
Managing certificates
Certificates are obtained and renewed with the certificate commands:
- create obtains a certificate from Let's Encrypt for the domain. Let's Encrypt verifies that you control the domain, so the domain must be set up to point at this host. Add
-s(--staging) to test against Let's Encrypt's staging service first - this avoids using up the limited number of real certificates while you get the setup right. - list shows the installed certificates and their expiry dates.
- renew renews any certificate that is due to expire within 30 days; passing a domain forces that one to renew. Run it regularly - for example as a daily scheduled task - so certificates never lapse. Certificates that are still well within their validity are left untouched.
Turning on TLS
TLS is enabled per endpoint, not on this page. Once a certificate exists for the relevant domain, the endpoint uses it:
- API Proxy - set
apiproxy.protocoltohttps. - SIP Server - use the
sips(5061) andwss(5081) ports.
FAQ
Do I need certificates?
Only if you use encrypted connections - secure SIP or HTTPS. Plain endpoints work without them. If you offer encrypted connections, you need a certificate for the domain clients use to reach SBN Media.
How do I stop certificates from expiring?
Run ./sbn-media certificate renew regularly, for example as a daily scheduled task. It renews anything within 30 days of expiry and leaves valid certificates alone, so it is safe to run often.
Can I test without using up my Let's Encrypt allowance?
Yes. Add -s (--staging) to certificate create to use Let's Encrypt's staging service while you get the setup working, then run it again without -s to obtain the real certificate.
Where are certificates stored?
As files - a certificate and a key per domain - in SBN Media's certificate directory. The encrypted endpoints load them from there automatically.
Can I use certificates other than Let's Encrypt?
Yes - follow the domain file name convention and it will be used by the services.
Related pages
- SBN Media Overview (
SBN-Media/overview) - Installing and Configuring SBN Media (
SBN-Media/installation) - SIP Server (
SBN-Media/Telephony/sip-server) - API Proxy (
SBN-Media/Platform/api-proxy)