# Self signed certificate

**URL:** <https://openvidu.discourse.group/t/self-signed-certificate/1228>\
**Category:** Issues with deployment\
**Tags:** v2\
**Created:** [June 19, 2020, 5:32pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228 "2020-06-19T17:32:31Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 19, 2020, 5:32pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/1 "2020-06-19T17:32:31Z")

</div>

Hi, could anyone help me with deployment? I have deployed OpenVidu on premises, I have only public IP, no domain name, so I generated self signed certificate and set the .env parameter to selfsigned, but how do I set the nginx in docker for this certificate?

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [June 19, 2020, 9:45pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/2 "2020-06-19T21:45:57Z")

</div>

Hi peyar!

If you set this parameter **`CERTIFICATE_TYPE`** , as `selfsigned` the nginx container will generate the certificate for you and you don’t need to create one or put any certificates anywhere.

So if you’re running OpenVidu CE, if I understand your deployment you only need to set this properties to run OpenVidu:

```auto
DOMAIN_OR_PUBLIC_IP=<YOUR_PUBLIC_IP>
OPENVIDU_SECRET=<YOUR_SECRET>
CERTIFICATE_TYPE=selfsigned

```

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 20, 2020, 12:03pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/3 "2020-06-20T12:03:06Z")

</div>

Thank You for the answer. However, the mentioned properties are set as You wrote, but on Win Firefox client I always get a notice about secure connaction failure with error PR\_END\_OF\_FILE\_ERROR. On other OS and other browsers there is another error, but always concerning secure connection failure. According to my search this may be caused by either missing certificate or port accessibility problems.

My environment is: OS ubuntu 16.04 xenial with older application running with apache, php, MariaDB (maybe this apache and nginx in docker port interference could be the problem?). docker and docker compose is installed and running, OpenVidu was deployed according to documentation and without errors, and it is running in docker container. ufw on ubuntu enabled and recommended ports allowed (I am not sure if all necessary ports, but I followed the documentation)

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [June 20, 2020, 12:28pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/4 "2020-06-20T12:28:13Z")

</div>

Can you try to open `https://<your_public_ip>/openvidu` and accept the certificate?

Also, please share your openvidu url so I can check the error by myself if it persits.

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 20, 2020, 12:57pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/5 "2020-06-20T12:57:02Z")

</div>

the `https://\<your\_public\_ip\>/openvidu is not accessible, no response, I can send You the public IP, I do not want to share it due to security reasons, because as I mentioned there is another application running on unsecure http on this server (port 80)

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 20, 2020, 1:05pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/6 "2020-06-20T13:05:40Z")

</div>

seems like there is no access to nginx in docker container at all, maybe I should check the apache settings?

---

<div class="post-metadata">

**Author:** ![micael.gallego](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/micael.gallego/32/2_2.png) [@micael.gallego](https://openvidu.discourse.group/u/micael.gallego)\
**Post date:** [June 20, 2020, 1:24pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/7 "2020-06-20T13:24:33Z")

</div>

It seems you have a problem with the NGINX included in OpenVidu. As is explained in the deployment instructions, 80 port should be available in the machine as NGINX uses it in case you want to use Let’s Encrypt.

If you want to deploy your own application on the same server, please follow these instructions:

[https://docs.openvidu.io/en/2.14.0/deployment/deploying-openvidu-apps/](https://docs.openvidu.io/en/2.14.0/deployment/deploying-openvidu-apps/)

Basically you have to use 5442 port in your own app so NGINX included in OpenVidu can redirect requests on port 80 to it.

Other possibility is to change HTTP\_PORT in OpenVidu config to other port so you can use 80 for your app

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 22, 2020, 11:38am UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/8 "2020-06-22T11:38:51Z")

</div>

Well, really it seems to be a problem or misconfiguration of my nginx in docker container. I have apache on my server serving tottaly different purpose and application. In apache I disabled ssl mod, I have set in .openvidu .env file parameter https\_port to 5443, I have opened ufw for this port, restarted openvidu, which told me that the services of openvidu should be accessible at [https://publicip:5443](https://publicip:5443), but I still get same ssl certificate error in my browser. seems like thee is no access to nginx in docker at all? should be the nginx in docker also reconfigured to use port 5443?

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 22, 2020, 11:41am UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/9 "2020-06-22T11:41:27Z")

</div>

and addtionally whe I restart the opnevidu, i can see a warning about configuring the proxy in front of openvidu

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 22, 2020, 12:42pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/10 "2020-06-22T12:42:07Z")

</div>

I have made another test in abuve mentioned configuration, when I stop openvidu, I cannot acces the page, when I restart openvidu, I have the SSL\_ERROR\_RX\_RECORD\_TOO\_LONG message in FF (other error message in other browsers). So, according to the test, the nginx responds on the 5443 port, but the is some problem with ssl certificate or the is still some nginx port misconfiguration

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [June 22, 2020, 2:17pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/11 "2020-06-22T14:17:47Z")

</div>

Hi peyar. You can’t expose port 5443, it is used by openvidu container, can you try with another port? For example 5448?

Also to help you, we need more information about your config. Can you share with us your .env files and your nginx-logs?

To print nginx-logs you can execute:

```auto
docker-compose logs nginx

```

Also, be sure to not modify docker-compose.yml files, only modify .env files in your deployment

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 22, 2020, 5:35pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/12 "2020-06-22T17:35:40Z")

</div>

well, I have set port 5448, did not edited yml files, restarted openvidu and no response from the server on https (nor https root neither https dashboard url) (on http port there is still apache listening for another application).  
my .env file - slightly shortened:

# OpenVidu configuration

# Domain name. If you do not have one, the public IP of the machine.

# `For example: 198.51.100.1, or openvidu.example.com`

DOMAIN\_OR\_PUBLIC\_IP=xxx.xxx.xx.xx

# OpenVidu SECRET used for apps to connect to OpenVidu server and users to access to OpenVidu Dashboard

OPENVIDU\_SECRET=xxxxxxxxxxxxx

# Certificate type:

CERTIFICATE\_TYPE=selfsigned

# If CERTIFICATE\_TYPE=letsencrypt, you need to configure a valid email for notifications

`LETSENCRYPT_EMAIL=user@example.com`

# Proxy configuration

# If you want to change the ports on which openvidu listens, uncomment the following lines

# HTTP\_PORT=80

# Changes the port of all services exposed by OpenVidu.

# SDKs, REST clients and browsers will have to connect to this port

HTTPS\_PORT=5448

# Access restrictions

# In this section you will be able to restrict the IPs from which you can access to

# Openvidu API and the Administration Panel

# WARNING! If you touch this configuration you can lose access to the platform from some IPs.

# Use it carefully.

# This section limits access to the /dashboard (OpenVidu CE) and /inspector (OpenVidu Pro) pages.

# The form for a single IP or an IP range is:

# ALLOWED\_ACCESS\_TO\_DASHBOARD=198.51.100.1 and ALLOWED\_ACCESS\_TO\_DASHBOARD=198.51.100.0/24

# To limit multiple IPs or IP ranges, separate by commas like this:

# ALLOWED\_ACCESS\_TO\_DASHBOARD=198.51.100.1, 198.51.100.0/24

# ALLOWED\_ACCESS\_TO\_DASHBOARD=

# This section limits access to the Openvidu REST API.

# The form for a single IP or an IP range is:

# ALLOWED\_ACCESS\_TO\_RESTAPI=198.51.100.1 and ALLOWED\_ACCESS\_TO\_RESTAPI=198.51.100.0/24

# To limit multiple IPs or or IP ranges, separate by commas like this:

# ALLOWED\_ACCESS\_TO\_RESTAPI=198.51.100.1, 198.51.100.0/24

# ALLOWED\_ACCESS\_TO\_RESTAPI=

# Whether to enable recording module or not

OPENVIDU\_RECORDING=false

# Openvidu Folder Record used for save the openvidu recording videos. Change it

# with the folder you want to use from your host.

OPENVIDU\_RECORDING\_PATH=/opt/openvidu/recordings

# System path where OpenVidu Server should look for custom recording layouts

OPENVIDU\_RECORDING\_CUSTOM\_LAYOUT=/opt/openvidu/custom-layout

# if true any client can connect to

# https://OPENVIDU\_SERVER\_IP:OPENVIDU\_PORT/recordings/any\_session\_file.mp4

# and access any recorded video file. If false this path will be secured with

# OPENVIDU\_SECRET param just as OpenVidu Server dashboard at

# https://OPENVIDU\_SERVER\_IP:OPENVIDU\_PORT

# Values: true | false

OPENVIDU\_RECORDING\_PUBLIC\_ACCESS=false

# Which users should receive the recording events in the client side

# (recordingStarted, recordingStopped). Can be all (every user connected to

# the session), publisher\_moderator (users with role ‘PUBLISHER’ or

# ‘MODERATOR’), moderator (only users with role ‘MODERATOR’) or none

# (no user will receive these events)

OPENVIDU\_RECORDING\_NOTIFICATION=publisher\_moderator

# Timeout in seconds for recordings to automatically stop (and the session involved to be closed)

# when conditions are met: a session recording is started but no user is publishing to it or a session

# is being recorded and last user disconnects. If a user publishes within the timeout in either case,

# the automatic stop of the recording is cancelled

# 0 means no timeout

OPENVIDU\_RECORDING\_AUTOSTOP\_TIMEOUT=120

# Maximum video bandwidth sent from clients to OpenVidu Server, in kbps.

# 0 means unconstrained

OPENVIDU\_STREAMS\_VIDEO\_MAX\_RECV\_BANDWIDTH=1000

# Minimum video bandwidth sent from clients to OpenVidu Server, in kbps.

# 0 means unconstrained

OPENVIDU\_STREAMS\_VIDEO\_MIN\_RECV\_BANDWIDTH=300

# Maximum video bandwidth sent from OpenVidu Server to clients, in kbps.

# 0 means unconstrained

OPENVIDU\_STREAMS\_VIDEO\_MAX\_SEND\_BANDWIDTH=1000

# Minimum video bandwidth sent from OpenVidu Server to clients, in kbps.

# 0 means unconstrained

OPENVIDU\_STREAMS\_VIDEO\_MIN\_SEND\_BANDWIDTH=300

# true to enable OpenVidu Webhook service. false’ otherwise

# Values: true | false

OPENVIDU\_WEBHOOK=false

# HTTP endpoint where OpenVidu Server will send Webhook HTTP POST messages

# Must be a valid URL: http(s)://ENDPOINT

#OPENVIDU\_WEBHOOK\_ENDPOINT=

# List of headers that OpenVidu Webhook service will attach to HTTP POST messages

#OPENVIDU\_WEBHOOK\_HEADERS=

# List of events that will be sent by OpenVidu Webhook service

# Leave blank if all events.

OPENVIDU\_WEBHOOK\_EVENTS=[sessionCreated,sessionDestroyed,participantJoined,participantLeft,webrtcConnectionCreated,webrtcConnectionDestroyed,recordingStatusChanged,filterEventDispatched,mediaNodeStatusChanged]

# How often the garbage collector of non active sessions runs.

# This helps cleaning up sessions that have been initialized through

# REST API (and maybe tokens have been created for them) but have had no users connected.

# Default to 900s (15 mins). 0 to disable non active sessions garbage collector

OPENVIDU\_SESSIONS\_GARBAGE\_INTERVAL=900

# Minimum time in seconds that a non active session must have been in existence

# for the garbage collector of non active sessions to remove it. Default to 3600s (1 hour).

# If non active sessions garbage collector is disabled

# (property ‘OPENVIDU\_SESSIONS\_GARBAGE\_INTERVAL’ to 0) this property is ignored

OPENVIDU\_SESSIONS\_GARBAGE\_THRESHOLD=3600

# Call Detail Record enabled

# Whether to enable Call Detail Record or not

# Values: true | false

OPENVIDU\_CDR=false

# Path where the cdr log files are hosted

OPENVIDU\_CDR\_PATH=/opt/openvidu/cdr

# Kurento Media Server image

# --------------------------

# Docker hub kurento media server: [https://hub.docker.com/r/kurento/kurento-media-server-dev](https://hub.docker.com/r/kurento/kurento-media-server-dev)

# Uncomment the next line and define this variable with KMS image that you want use

# KMS\_IMAGE=kurento/kurento-media-server-dev:6.13

# Kurento Media Server Level logs

# -------------------------------

# Uncomment the next line and define this variable to change

# the verbosity level of the logs of KMS

# KMS\_DEBUG\_LEVEL=3,Kurento\*:4,kms\*:4,sdp\*:4,webrtc\*:4,_rtpendpoint:4,rtp_handler:4,rtpsynchronizer:4,agnosticbin:4

# Openvidu Server Level logs

# --------------------------

# Uncomment the next line and define this variable to change

# the verbosity level of the logs of Openvidu Service

# RECOMENDED VALUES: INFO for normal logs DEBUG for more verbose logs

# OV\_CE\_DEBUG\_LEVEL=INFO

# Java Options

# --------------------------

# Uncomment the next line and define this to add

# options to java command

# JAVA\_OPTIONS=-Xms2048m -Xmx4096m -Duser.timezone=UTC

and my nginx logs

Attaching to openvidu\_nginx\_1  
nginx\_1 | 2020/06/22 16:38:58 [emerg] 7#7: listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | nginx: [emerg] listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | 2020/06/22 16:38:58 [emerg] 7#7: listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | nginx: [emerg] listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | 2020/06/22 16:38:58 [emerg] 7#7: listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | nginx: [emerg] listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | 2020/06/22 16:38:58 [emerg] 7#7: listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | nginx: [emerg] listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | 2020/06/22 16:38:58 [emerg] 7#7: listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | nginx: [emerg] listen() to 0.0.0.0:80, backlog 511 failed (98: Address in use)  
nginx\_1 | 2020/06/22 16:38:58 [emerg] 7#7: still could not bind()  
nginx\_1 | nginx: [emerg] still could not bind()  
nginx\_1 |  
nginx\_1 | =======================================  
nginx\_1 | = INPUT VARIABLES =  
nginx\_1 | =======================================  
nginx\_1 |  
nginx\_1 | Config NGINX:  
nginx\_1 | - Http Port: 80  
nginx\_1 | - Https Port: 5448  
nginx\_1 | - Allowed Access in Openvidu Dashboard: all  
nginx\_1 | - Allowed Access in Openvidu API: all  
nginx\_1 |  
nginx\_1 | Config Openvidu Application:  
nginx\_1 | - Domain name: xxx.xxx.xx.xx  
nginx\_1 | - Certificated: selfsigned  
nginx\_1 | - Letsencrypt Email: [user@example.com](mailto:user@example.com)  
nginx\_1 | - Openvidu Application: true  
nginx\_1 | - Openvidu Application Type: CE  
nginx\_1 |  
nginx\_1 | =======================================  
nginx\_1 | = CONFIGURATION NGINX =  
nginx\_1 | =======================================  
nginx\_1 |  
nginx\_1 | Configure xxx.xxx.xxx.xxx domain…  
nginx\_1 | - New configuration: selfsigned  
nginx\_1 | - Old configuration: selfsigned  
nginx\_1 | - Selfsigned certificate already exists, using them…  
nginx\_1 |  
nginx\_1 | =======================================  
nginx\_1 | = ALLOWED ACCESS =  
nginx\_1 | =======================================  
nginx\_1 |  
nginx\_1 | Adding rules…  
nginx\_1 |  
nginx\_1 | Finish Rules:  
nginx\_1 | Openvidu Dashboard:  
nginx\_1 | - allow all;  
nginx\_1 | Openvidu API:  
nginx\_1 | - allow all;  
nginx\_1 |  
nginx\_1 | =======================================  
nginx\_1 | = START OPENVIDU PROXY =  
nginx\_1 | =======================================  
nginx\_1 |  
nginx\_1 | 2020/06/22 16:39:00 [warn] 53#53: “ssl\_stapling” ignored, no OCSP responder URL in the certificate “/etc/letsencrypt/live/xxx.xxx.xxx.xxx/fullchain.pem”  
nginx\_1 | nginx: [warn] “ssl\_stapling” ignored, no OCSP responder URL in the certificate “/etc/letsencrypt/live/xxx.xxx.xxx.xxx/fullchain.pem”  
nginx\_1 | 2020/06/22 16:39:00 [notice] 53#53: signal process started  
nginx\_1 | 2020/06/22 16:39:00 [error] 53#53: open() “/var/run/nginx.pid” failed (2: No such file or directory)  
nginx\_1 | nginx: [error] open() “/var/run/nginx.pid” failed (2: No such file or directory)  
nginx\_1 | ==\> /var/log/nginx/access.log \<==

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [June 22, 2020, 6:08pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/13 "2020-06-22T18:08:02Z")

</div>

Please, use markdown format to share logs and configuration files. That’s impossible to read or use… Don’t paste it directly because it appears with comments as headers.

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 22, 2020, 6:39pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/14 "2020-06-22T18:39:56Z")

</div>

I apologize, hope this is better

# OpenVidu configuration  
# ----------------------

# NOTE: This file doesn’t need to quote assignment values, like most shells do.  
# All values are stored as-is, even if they contain spaces, so don’t quote them.

# Domain name. If you do not have one, the public IP of the machine.  
# For example: 198.51.100.1, or  
DOMAIN\_OR\_PUBLIC\_IP=xxx.xxx.xx.xx

# OpenVidu SECRET used for apps to connect to OpenVidu server and users to access to OpenVidu Dashboard  
OPENVIDU\_SECRET=xxxxxxxxxxxxx

# Certificate type:  
# - selfsigned: Self signed certificate. Not recommended for production use.  
# Users will see an ERROR when connected to web page.  
# - owncert: Valid certificate purchased in a Internet services company.  
# Please put the certificates files inside folder ./owncert  
# with names certificate.key and certificate.cert  
# - letsencrypt: Generate a new certificate using letsencrypt. Please set the  
# required contact email for Let’s Encrypt in LETSENCRYPT\_EMAIL  
# variable.  
CERTIFICATE\_TYPE=selfsigned

# If CERTIFICATE\_TYPE=letsencrypt, you need to configure a valid email for notifications  
[LETSENCRYPT\_EMAIL=user@example.com](mailto:LETSENCRYPT_EMAIL=user@example.com)

# Proxy configuration  
# If you want to change the ports on which openvidu listens, uncomment the following lines

# Allows any request to http://DOMAIN\_OR\_PUBLIC\_IP:HTTP\_PORT/ to be automatically  
# redirected to https://DOMAIN\_OR\_PUBLIC\_IP:HTTPS\_PORT/.  
# WARNING: the default port 80 cannot be changed during the first boot  
# if you have chosen to deploy with the option CERTIFICATE\_TYPE=letsencrypt  
# HTTP\_PORT=80

# Changes the port of all services exposed by OpenVidu.  
# SDKs, REST clients and browsers will have to connect to this port  
HTTPS\_PORT=5448

# Access restrictions  
# In this section you will be able to restrict the IPs from which you can access to  
# Openvidu API and the Administration Panel  
# WARNING! If you touch this configuration you can lose access to the platform from some IPs.  
# Use it carefully.

# This section limits access to the /dashboard (OpenVidu CE) and /inspector (OpenVidu Pro) pages.  
# The form for a single IP or an IP range is:  
# ALLOWED\_ACCESS\_TO\_DASHBOARD=198.51.100.1 and ALLOWED\_ACCESS\_TO\_DASHBOARD=198.51.100.0/24  
# To limit multiple IPs or IP ranges, separate by commas like this:  
# ALLOWED\_ACCESS\_TO\_DASHBOARD=198.51.100.1, 198.51.100.0/24  
# ALLOWED\_ACCESS\_TO\_DASHBOARD=

# This section limits access to the Openvidu REST API.  
# The form for a single IP or an IP range is:  
# ALLOWED\_ACCESS\_TO\_RESTAPI=198.51.100.1 and ALLOWED\_ACCESS\_TO\_RESTAPI=198.51.100.0/24  
# To limit multiple IPs or or IP ranges, separate by commas like this:  
# ALLOWED\_ACCESS\_TO\_RESTAPI=198.51.100.1, 198.51.100.0/24  
# ALLOWED\_ACCESS\_TO\_RESTAPI=

# Whether to enable recording module or not  
OPENVIDU\_RECORDING=false

# Openvidu Folder Record used for save the openvidu recording videos. Change it  
# with the folder you want to use from your host.  
OPENVIDU\_RECORDING\_PATH=/opt/openvidu/recordings

# System path where OpenVidu Server should look for custom recording layouts  
OPENVIDU\_RECORDING\_CUSTOM\_LAYOUT=/opt/openvidu/custom-layout

# if true any client can connect to  
# https://OPENVIDU\_SERVER\_IP:OPENVIDU\_PORT/recordings/any\_session\_file.mp4  
# and access any recorded video file. If false this path will be secured with  
# OPENVIDU\_SECRET param just as OpenVidu Server dashboard at  
# https://OPENVIDU\_SERVER\_IP:OPENVIDU\_PORT  
# Values: true | false  
OPENVIDU\_RECORDING\_PUBLIC\_ACCESS=false

# Which users should receive the recording events in the client side  
# (recordingStarted, recordingStopped). Can be all (every user connected to  
# the session), publisher\_moderator (users with role ‘PUBLISHER’ or  
# ‘MODERATOR’), moderator (only users with role ‘MODERATOR’) or none  
# (no user will receive these events)  
OPENVIDU\_RECORDING\_NOTIFICATION=publisher\_moderator

# Timeout in seconds for recordings to automatically stop (and the session involved to be closed)  
# when conditions are met: a session recording is started but no user is publishing to it or a session  
# is being recorded and last user disconnects. If a user publishes within the timeout in either case,  
# the automatic stop of the recording is cancelled  
# 0 means no timeout  
OPENVIDU\_RECORDING\_AUTOSTOP\_TIMEOUT=120

# Maximum video bandwidth sent from clients to OpenVidu Server, in kbps.  
# 0 means unconstrained  
OPENVIDU\_STREAMS\_VIDEO\_MAX\_RECV\_BANDWIDTH=1000

# Minimum video bandwidth sent from clients to OpenVidu Server, in kbps.  
# 0 means unconstrained  
OPENVIDU\_STREAMS\_VIDEO\_MIN\_RECV\_BANDWIDTH=300

# Maximum video bandwidth sent from OpenVidu Server to clients, in kbps.  
# 0 means unconstrained  
OPENVIDU\_STREAMS\_VIDEO\_MAX\_SEND\_BANDWIDTH=1000

# Minimum video bandwidth sent from OpenVidu Server to clients, in kbps.  
# 0 means unconstrained  
OPENVIDU\_STREAMS\_VIDEO\_MIN\_SEND\_BANDWIDTH=300

# true to enable OpenVidu Webhook service. false’ otherwise  
# Values: true | false  
OPENVIDU\_WEBHOOK=false

# HTTP endpoint where OpenVidu Server will send Webhook HTTP POST messages  
# Must be a valid URL: http(s)://ENDPOINT  
#OPENVIDU\_WEBHOOK\_ENDPOINT=

# List of headers that OpenVidu Webhook service will attach to HTTP POST messages  
#OPENVIDU\_WEBHOOK\_HEADERS=

# List of events that will be sent by OpenVidu Webhook service  
# Leave blank if all events.  
OPENVIDU\_WEBHOOK\_EVENTS=[sessionCreated,sessionDestroyed,participantJoined,participantLeft,webrtcConnectionCreated,webrtcConnectionDestroyed,recordingStatusChanged,filterEventDispatched,mediaNodeStatusChanged]

# How often the garbage collector of non active sessions runs.  
# This helps cleaning up sessions that have been initialized through  
# REST API (and maybe tokens have been created for them) but have had no users connected.  
# Default to 900s (15 mins). 0 to disable non active sessions garbage collector  
OPENVIDU\_SESSIONS\_GARBAGE\_INTERVAL=900

# Minimum time in seconds that a non active session must have been in existence  
# for the garbage collector of non active sessions to remove it. Default to 3600s (1 hour).  
# If non active sessions garbage collector is disabled  
# (property ‘OPENVIDU\_SESSIONS\_GARBAGE\_INTERVAL’ to 0) this property is ignored  
OPENVIDU\_SESSIONS\_GARBAGE\_THRESHOLD=3600

# Call Detail Record enabled  
# Whether to enable Call Detail Record or not  
# Values: true | false  
OPENVIDU\_CDR=false

# Path where the cdr log files are hosted  
OPENVIDU\_CDR\_PATH=/opt/openvidu/cdr

# Kurento Media Server image  
# --------------------------  
# Docker hub kurento media server:  
# Uncomment the next line and define this variable with KMS image that you want use  
# KMS\_IMAGE=kurento/kurento-media-server-dev:6.13

# Kurento Media Server Level logs  
# -------------------------------  
# Uncomment the next line and define this variable to change  
# the verbosity level of the logs of KMS  
# Documentation:  
# KMS\_DEBUG\_LEVEL=3,Kurento\*:4,kms\*:4,sdp\*:4,webrtc\*:4,_rtpendpoint:4,rtp_handler:4,rtpsynchronizer:4,agnosticbin:4

# Openvidu Server Level logs  
# --------------------------  
# Uncomment the next line and define this variable to change  
# the verbosity level of the logs of Openvidu Service  
# RECOMENDED VALUES: INFO for normal logs DEBUG for more verbose logs  
# OV\_CE\_DEBUG\_LEVEL=INFO

# Java Options  
# --------------------------  
# Uncomment the next line and define this to add  
# options to java command  
# JAVA\_OPTIONS=-Xms2048m -Xmx4096m -Duser.timezone=UTC

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 22, 2020, 9:13pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/15 "2020-06-22T21:13:23Z")

</div>

and after openvidu restart:

Stopping openvidu\_app\_1 … done  
Stopping openvidu\_coturn\_1 … done  
Stopping openvidu\_kms\_1 … done  
Stopping openvidu\_openvidu-server\_1 … done  
Stopping openvidu\_redis\_1 … done  
Stopping openvidu\_nginx\_1 … done  
Removing openvidu\_app\_1 … done  
Removing openvidu\_coturn\_1 … done  
Removing openvidu\_kms\_1 … done  
Removing openvidu\_openvidu-server\_1 … done  
Removing openvidu\_redis\_1 … done  
Removing openvidu\_nginx\_1 … done  
Removing network openvidu\_default  
Creating network “openvidu\_default” with the default driver  
Creating openvidu\_redis\_1 … done  
Creating openvidu\_nginx\_1 … done  
Creating openvidu\_app\_1 … done  
Creating openvidu\_openvidu-server\_1 … done  
Creating openvidu\_kms\_1 … done  
Creating openvidu\_coturn\_1 … done  
Attaching to openvidu\_openvidu-server\_1  
openvidu-server\_1 |  
openvidu-server\_1 |  
openvidu-server\_1 | =======================================  
openvidu-server\_1 | = LAUNCH OPENVIDU-SERVER =  
openvidu-server\_1 | =======================================  
openvidu-server\_1 |  
openvidu-server\_1 | \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_  
openvidu-server\_1 | \_\_\_\_ \_\_ \_\_\_ \_  
openvidu-server\_1 | / \_\_ \ \ \ / (_) | |  
openvidu-server\_1 | | | | |_ \_\_ \_\_\_ \_ _\ \ / / \_ | | \_  
openvidu-server\_1 | | | | | ’ \ / \_ \ ’_ \ / / | |/ _` | | | |  
openvidu-server\_1 | | |\_\_| | |_) | **/ | | \ / | | (_| | |_| |  
openvidu-server\_1 | \_**_/| . __/ \__ \_|_| |_|/ |_|\ __,_|\__ ,_|  
openvidu-server\_1 | | |  
openvidu-server\_1 | |_| version 2.14.0  
openvidu-server\_1 | \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_  
openvidu-server\_1 |  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:18,981 [main] io.openvidu.server.OpenViduServer - Starting OpenViduServer on peyarTC with PID 19 (/openvidu-server.jar started by root in /)  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:18,984 [main] io.openvidu.server.OpenViduServer - No active profile set, falling back to default profiles: default  
openvidu-server\_1 | [ERROR] 2020-06-22 21:04:19,131 [main] io.openvidu.server.config.OpenviduConfig - .env file not found at /./.env  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:19,218 [main] io.openvidu.server.OpenViduServer - Started OpenViduServer in 1.019 seconds (JVM running for 1.419)  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:19,221 [main] io.openvidu.server.OpenViduServer -  
openvidu-server\_1 |  
openvidu-server\_1 |  
openvidu-server\_1 | Configuration properties  
openvidu-server\_1 | ------------------------  
openvidu-server\_1 |  
openvidu-server\_1 | \* CERTIFICATE\_TYPE=selfsigned  
openvidu-server\_1 | \* DOMAIN\_OR\_PUBLIC\_IP=xx.xx.xx.xx  
openvidu-server\_1 | \* HTTPS\_PORT=443  
openvidu-server\_1 | \* KMS\_URIS=[“ws://localhost:8888/kurento”]  
openvidu-server\_1 | \* OPENVIDU\_CDR=false  
openvidu-server\_1 | \* OPENVIDU\_CDR\_PATH=/opt/openvidu/cdr  
openvidu-server\_1 | \* OPENVIDU\_RECORDING=false  
openvidu-server\_1 | \* OPENVIDU\_RECORDING\_AUTOSTOP\_TIMEOUT=120  
openvidu-server\_1 | \* OPENVIDU\_RECORDING\_COMPOSED\_URL=  
openvidu-server\_1 | \* OPENVIDU\_RECORDING\_CUSTOM\_LAYOUT=/opt/openvidu/custom-layout  
openvidu-server\_1 | \* OPENVIDU\_RECORDING\_NOTIFICATION=publisher\_moderator  
openvidu-server\_1 | \* OPENVIDU\_RECORDING\_PATH=/opt/openvidu/recordings  
openvidu-server\_1 | \* OPENVIDU\_RECORDING\_PUBLIC\_ACCESS=false  
openvidu-server\_1 | \* OPENVIDU\_RECORDING\_VERSION=2.9.0  
openvidu-server\_1 | \* OPENVIDU\_SECRET=xxxxxxxxx  
openvidu-server\_1 | \* OPENVIDU\_SESSIONS\_GARBAGE\_INTERVAL=900  
openvidu-server\_1 | \* OPENVIDU\_SESSIONS\_GARBAGE\_THRESHOLD=3600  
openvidu-server\_1 | \* OPENVIDU\_STREAMS\_VIDEO\_MAX\_RECV\_BANDWIDTH=1000  
openvidu-server\_1 | \* OPENVIDU\_STREAMS\_VIDEO\_MAX\_SEND\_BANDWIDTH=1000  
openvidu-server\_1 | \* OPENVIDU\_STREAMS\_VIDEO\_MIN\_RECV\_BANDWIDTH=300  
openvidu-server\_1 | \* OPENVIDU\_STREAMS\_VIDEO\_MIN\_SEND\_BANDWIDTH=300  
openvidu-server\_1 | \* OPENVIDU\_WEBHOOK=false  
openvidu-server\_1 | \* OPENVIDU\_WEBHOOK\_ENDPOINT=  
openvidu-server\_1 | \* OPENVIDU\_WEBHOOK\_EVENTS=[sessionCreated,sessionDestroyed,participantJoined,participantLeft,webrtcConnectionCreated,webrtcConnectionDestroyed,recordingStatusChanged,filterEventDispatched,mediaNodeStatusChanged]  
openvidu-server\_1 | \* OPENVIDU\_WEBHOOK\_HEADERS=[]  
openvidu-server\_1 |  
openvidu-server\_1 |  
openvidu-server\_1 |  
openvidu-server\_1 | [WARN] 2020-06-22 21:04:19,225 [main] io.openvidu.server.OpenViduServer - You have set property server.port (or SERVER\_PORT). This will serve OpenVidu Server on your host at port 5443. But property HTTPS\_PORT (443) still configures the port that should be used to connect to OpenVidu Server from outside. Bear this in mind when configuring a proxy in front of OpenVidu Server  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:19,225 [main] io.openvidu.server.OpenViduServer - Using /dev/urandom for secure random generation  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:19,297 [main] io.openvidu.server.OpenViduServer - Starting OpenViduServer on peyarTC with PID 19 (/openvidu-server.jar started by root in /)  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:19,297 [main] io.openvidu.server.OpenViduServer - No active profile set, falling back to default profiles: default  
openvidu-server\_1 | [ERROR] 2020-06-22 21:04:20,087 [main] io.openvidu.server.config.OpenviduConfig - .env file not found at /./.env  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,299 [main] org.springframework.boot.web.embedded.tomcat.TomcatWebServer - Tomcat initialized with port(s): 5443 (http)  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,310 [main] org.apache.coyote.http11.Http11NioProtocol - Initializing ProtocolHandler [“http-nio-0.0.0.0-5443”]  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,311 [main] org.apache.catalina.core.StandardService - Starting service [Tomcat]  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,311 [main] org.apache.catalina.core.StandardEngine - Starting Servlet engine: [Apache Tomcat/9.0.30]  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,368 [main] org.apache.catalina.core.ContainerBase.[Tomcat].[localhost].[/] - Initializing Spring embedded WebApplicationContext  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,369 [main] org.springframework.web.context.ContextLoader - Root WebApplicationContext: initialization completed in 1042 ms  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,659 [main] io.openvidu.server.OpenViduServer - OpenVidu CDR service is disabled (may be enable with ‘OPENVIDU\_CDR=true’)  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,659 [main] io.openvidu.server.OpenViduServer - OpenVidu Webhook service is disabled (may be enabled with ‘OPENVIDU\_WEBHOOK=true’)  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,673 [main] io.openvidu.server.OpenViduServer - OpenVidu Server using one KMS: ws://localhost:8888/kurento  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,696 [rbeatExec-e1-t0] org.kurento.jsonrpc.client.JsonRpcClientNettyWebSocket - [KurentoClient] Connecting native client  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,696 [rbeatExec-e1-t0] org.kurento.jsonrpc.client.JsonRpcClientNettyWebSocket - [KurentoClient] Creating new NioEventLoopGroup  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,810 [ntLoopGroup-2-1] org.kurento.jsonrpc.client.JsonRpcClientNettyWebSocket - [KurentoClient] Initiating new Netty channel. Will create new handler too!  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,915 [EventExec-e2-t0] io.openvidu.server.kurento.kms.KmsManager - Kurento Client “connected” event for KMS ws://localhost:8888/kurento [org.kurento.client.KurentoClient@387ebcfb]  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,917 [main] io.openvidu.server.recording.service.RecordingManager - OpenVidu recording service is disabled  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,933 [main] io.openvidu.server.coturn.CoturnCredentialsService - COTURN IP: xx.xx.xx.xx  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,933 [main] io.openvidu.server.coturn.CoturnCredentialsService - COTURN Redis DB accessible with string “ip=127.0.0.1 dbname=0 password=turn connect\_timeout=30”  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,933 [main] io.openvidu.server.coturn.CoturnCredentialsService - Cleaning COTURN DB…  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,933 [main] io.openvidu.server.coturn.CoturnCredentialsService - Path of COTURN log files: /var/log/  
openvidu-server\_1 | [ERROR] 2020-06-22 21:04:20,935 [main] io.openvidu.server.coturn.CoturnCredentialsService - COTURN DB is not empty  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,935 [main] io.openvidu.server.coturn.CoturnCredentialsService - Using COTURN credentials service for BASH environment  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,943 [main] io.openvidu.server.core.SessionManager - Garbage collector for non active sessions initialized. Running every 900 seconds and cleaning up non active Sessions more than 3600 seconds old  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:20,974 [main] org.springframework.scheduling.concurrent.ThreadPoolTaskScheduler - Initializing ExecutorService ‘jsonrpcTaskScheduler’  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:21,124 [main] org.springframework.scheduling.concurrent.ThreadPoolTaskExecutor - Initializing ExecutorService ‘applicationTaskExecutor’  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:21,227 [main] org.springframework.boot.autoconfigure.web.servlet.WelcomePageHandlerMapping - Adding welcome page: class path resource [static/index.html]  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:21,417 [main] org.springframework.security.web.DefaultSecurityFilterChain - Creating filter chain: any request, [org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@34f7cfd9, org.springframework.security.web.context.SecurityContextPersistenceFilter@3541cb24, org.springframework.security.web.header.HeaderWriterFilter@5136d012, org.springframework.web.filter.CorsFilter@661972b0, org.springframework.security.web.authentication.logout.LogoutFilter@55b53d44, org.springframework.security.web.authentication.www.BasicAuthenticationFilter@10959ece, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@40cb8df7, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@355ce81c, org.springframework.security.web.authentication.AnonymousAuthenticationFilter@65f095f8, org.springframework.security.web.session.SessionManagementFilter@e1de817, org.springframework.security.web.access.ExceptionTranslationFilter@306cf3ea, org.springframework.security.web.access.intercept.FilterSecurityInterceptor@49dc7102]  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:21,454 [main] org.apache.coyote.http11.Http11NioProtocol - Starting ProtocolHandler [“http-nio-0.0.0.0-5443”]  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:21,478 [main] org.springframework.boot.web.embedded.tomcat.TomcatWebServer - Tomcat started on port(s): 5443 (http) with context path ‘’  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:21,479 [main] io.openvidu.server.OpenViduServer - Started OpenViduServer in 2.24 seconds (JVM running for 3.68)  
openvidu-server\_1 | [INFO] 2020-06-22 21:04:21,480 [main] io.openvidu.server.OpenViduServer -  
openvidu-server\_1 |  
openvidu-server\_1 | ----------------------------------------------------  
openvidu-server\_1 |  
openvidu-server\_1 | OpenVidu is ready!  
openvidu-server\_1 | ---------------------------  
openvidu-server\_1 |  
openvidu-server\_1 | \* OpenVidu Server: [https://xx.xx.xx.xx/](https://xx.xx.xx.xx/)  
openvidu-server\_1 |  
openvidu-server\_1 | \* OpenVidu Dashboard: [https://xx.xx.xx.xx/dashboard/](https://xx.xx.xx.xx/dashboard/)  
openvidu-server\_1 |  
openvidu-server\_1 | ----------------------------------------------------  
openvidu-server\_1 |

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 22, 2020, 9:15pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/16 "2020-06-22T21:15:15Z")

</div>

this last log is after disabling https port .env setting, leaving default 443

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [June 24, 2020, 4:38pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/17 "2020-06-24T16:38:05Z")

</div>

I’ve tried your same configuration and you’re right. I’ve launched another nginx instance using port 80, and then OpenVidu nginx can’t start. I managed to make it work by using a random `HTTP_PORT` value in .env file. In this way you can override the port 80 default value. You can do this in your .env file for example:

```auto
# OpenVidu configuration
# ----------------------

# NOTE: This file doesn’t need to quote assignment values, like most shells do.
# All values are stored as-is, even if they contain spaces, so don’t quote them.

# Domain name. If you do not have one, the public IP of the machine.
# For example: 198.51.100.1, or
DOMAIN_OR_PUBLIC_IP=xxx.xxx.xx.xx

# OpenVidu SECRET used for apps to connect to OpenVidu server and users to access to OpenVidu Dashboard
OPENVIDU_SECRET=xxxxxxxxxxxxx

# Certificate type:
# - selfsigned: Self signed certificate. Not recommended for production use.
# Users will see an ERROR when connected to web page.
# - owncert: Valid certificate purchased in a Internet services company.
# Please put the certificates files inside folder ./owncert
# with names certificate.key and certificate.cert
# - letsencrypt: Generate a new certificate using letsencrypt. Please set the
# required contact email for Let’s Encrypt in LETSENCRYPT_EMAIL
# variable.
CERTIFICATE_TYPE=selfsigned

# If CERTIFICATE_TYPE=letsencrypt, you need to configure a valid email for notifications
LETSENCRYPT_EMAIL=user@example.com

# Proxy configuration
# If you want to change the ports on which openvidu listens, uncomment the following lines

# Allows any request to http://DOMAIN_OR_PUBLIC_IP:HTTP_PORT/ to be automatically
# redirected to https://DOMAIN_OR_PUBLIC_IP:HTTPS_PORT/.
# WARNING: the default port 80 cannot be changed during the first boot
# if you have chosen to deploy with the option CERTIFICATE_TYPE=letsencrypt
HTTP_PORT=5678 # <--- You can use anyone you want, but not 80

# Changes the port of all services exposed by OpenVidu.
# SDKs, REST clients and browsers will have to connect to this port
# HTTPS_PORT=

# Access restrictions
# In this section you will be able to restrict the IPs from which you can access to
# Openvidu API and the Administration Panel
# WARNING! If you touch this configuration you can lose access to the platform from some IPs.
# Use it carefully.

# This section limits access to the /dashboard (OpenVidu CE) and /inspector (OpenVidu Pro) pages.
# The form for a single IP or an IP range is:
# ALLOWED_ACCESS_TO_DASHBOARD=198.51.100.1 and ALLOWED_ACCESS_TO_DASHBOARD=198.51.100.0/24
# To limit multiple IPs or IP ranges, separate by commas like this:
# ALLOWED_ACCESS_TO_DASHBOARD=198.51.100.1, 198.51.100.0/24
# ALLOWED_ACCESS_TO_DASHBOARD=

# This section limits access to the Openvidu REST API.
# The form for a single IP or an IP range is:
# ALLOWED_ACCESS_TO_RESTAPI=198.51.100.1 and ALLOWED_ACCESS_TO_RESTAPI=198.51.100.0/24
# To limit multiple IPs or or IP ranges, separate by commas like this:
# ALLOWED_ACCESS_TO_RESTAPI=198.51.100.1, 198.51.100.0/24
# ALLOWED_ACCESS_TO_RESTAPI=

# Whether to enable recording module or not
OPENVIDU_RECORDING=false

# Openvidu Folder Record used for save the openvidu recording videos. Change it
# with the folder you want to use from your host.
OPENVIDU_RECORDING_PATH=/opt/openvidu/recordings

# System path where OpenVidu Server should look for custom recording layouts
OPENVIDU_RECORDING_CUSTOM_LAYOUT=/opt/openvidu/custom-layout

# if true any client can connect to
# https://OPENVIDU_SERVER_IP:OPENVIDU_PORT/recordings/any_session_file.mp4
# and access any recorded video file. If false this path will be secured with
# OPENVIDU_SECRET param just as OpenVidu Server dashboard at
# https://OPENVIDU_SERVER_IP:OPENVIDU_PORT
# Values: true | false
OPENVIDU_RECORDING_PUBLIC_ACCESS=false

# Which users should receive the recording events in the client side
# (recordingStarted, recordingStopped). Can be all (every user connected to
# the session), publisher_moderator (users with role ‘PUBLISHER’ or
# ‘MODERATOR’), moderator (only users with role ‘MODERATOR’) or none
# (no user will receive these events)
OPENVIDU_RECORDING_NOTIFICATION=publisher_moderator

# Timeout in seconds for recordings to automatically stop (and the session involved to be closed)
# when conditions are met: a session recording is started but no user is publishing to it or a session
# is being recorded and last user disconnects. If a user publishes within the timeout in either case,
# the automatic stop of the recording is cancelled
# 0 means no timeout
OPENVIDU_RECORDING_AUTOSTOP_TIMEOUT=120

# Maximum video bandwidth sent from clients to OpenVidu Server, in kbps.
# 0 means unconstrained
OPENVIDU_STREAMS_VIDEO_MAX_RECV_BANDWIDTH=1000

# Minimum video bandwidth sent from clients to OpenVidu Server, in kbps.
# 0 means unconstrained
OPENVIDU_STREAMS_VIDEO_MIN_RECV_BANDWIDTH=300

# Maximum video bandwidth sent from OpenVidu Server to clients, in kbps.
# 0 means unconstrained
OPENVIDU_STREAMS_VIDEO_MAX_SEND_BANDWIDTH=1000

# Minimum video bandwidth sent from OpenVidu Server to clients, in kbps.
# 0 means unconstrained
OPENVIDU_STREAMS_VIDEO_MIN_SEND_BANDWIDTH=300

# true to enable OpenVidu Webhook service. false’ otherwise
# Values: true | false
OPENVIDU_WEBHOOK=false

# HTTP endpoint where OpenVidu Server will send Webhook HTTP POST messages
# Must be a valid URL: http(s)://ENDPOINT
#OPENVIDU_WEBHOOK_ENDPOINT=

# List of headers that OpenVidu Webhook service will attach to HTTP POST messages
#OPENVIDU_WEBHOOK_HEADERS=

# List of events that will be sent by OpenVidu Webhook service
# Leave blank if all events.
OPENVIDU_WEBHOOK_EVENTS=[sessionCreated,sessionDestroyed,participantJoined,participantLeft,webrtcConnectionCreated,webrtcConnectionDestroyed,recordingStatusChanged,filterEventDispatched,mediaNodeStatusChanged]

# How often the garbage collector of non active sessions runs.
# This helps cleaning up sessions that have been initialized through
# REST API (and maybe tokens have been created for them) but have had no users connected.
# Default to 900s (15 mins). 0 to disable non active sessions garbage collector
OPENVIDU_SESSIONS_GARBAGE_INTERVAL=900

# Minimum time in seconds that a non active session must have been in existence
# for the garbage collector of non active sessions to remove it. Default to 3600s (1 hour).
# If non active sessions garbage collector is disabled
# (property ‘OPENVIDU_SESSIONS_GARBAGE_INTERVAL’ to 0) this property is ignored
OPENVIDU_SESSIONS_GARBAGE_THRESHOLD=3600

# Call Detail Record enabled
# Whether to enable Call Detail Record or not
# Values: true | false
OPENVIDU_CDR=false

# Path where the cdr log files are hosted
OPENVIDU_CDR_PATH=/opt/openvidu/cdr

# Kurento Media Server image
# --------------------------
# Docker hub kurento media server:
# Uncomment the next line and define this variable with KMS image that you want use
# KMS_IMAGE=kurento/kurento-media-server-dev:6.13

# Kurento Media Server Level logs
# -------------------------------
# Uncomment the next line and define this variable to change
# the verbosity level of the logs of KMS
# Documentation:
# KMS_DEBUG_LEVEL=3,Kurento*:4,kms*:4,sdp*:4,webrtc*:4,rtpendpoint:4,rtphandler:4,rtpsynchronizer:4,agnosticbin:4

# Openvidu Server Level logs
# --------------------------
# Uncomment the next line and define this variable to change
# the verbosity level of the logs of Openvidu Service
# RECOMENDED VALUES: INFO for normal logs DEBUG for more verbose logs
# OV_CE_DEBUG_LEVEL=INFO

# Java Options
# --------------------------
# Uncomment the next line and define this to add
# options to java command
# JAVA_OPTIONS=-Xms2048m -Xmx4096m -Duser.timezone=UTC

```

Keep in mind that requests to port 80 will not redirect to https OpenVidu Server if you use this configuration. Also if you will use Let’s encrypt in the future, it will not work because it needs to have port 80 available.

Regards,  
Carlos

---

<div class="post-metadata">

**Author:** ![peyar](https://avatars.discourse-cdn.com/v4/letter/p/eada6e/32.png) [@peyar](https://openvidu.discourse.group/u/peyar)\
**Post date:** [June 24, 2020, 5:02pm UTC](https://openvidu.discourse.group/t/self-signed-certificate/1228/18 "2020-06-24T17:02:31Z")

</div>

Thank You very much for Your time spent with my question, I’ve tried to set another http port and it works. You saved me many hours trying to find out what is happening. And thanks for prompt responses.

Jaroslav Petras (peyar)
