# SSL issues on ubuntu deployment after upgrade

**URL:** <https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281>\
**Category:** Issues with deployment\
**Tags:** v2\
**Created:** [November 18, 2020, 1:40pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281 "2020-11-18T13:40:09Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamesroche](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jamesroche](https://openvidu.discourse.group/u/jamesroche)\
**Post date:** [November 18, 2020, 1:40pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/1 "2020-11-18T13:40:10Z")

</div>

So I just upgraded from version 11, I originally used java keystores for my SSL certificate and now I have issues getting the correct SSL certificate to load.

I have added a folder alongside my .env file called owncert and added in what I think are the correct certificates. when I boot VIDU up it looks as though it works, there are no signs that SSL certificates were not found or were invalid, etc but when I browse to the openvidu url I am getting a OpenVidu signed certificate.

Is there somewhere i can check for SSL errors during bootup? I have also tried enabling letencrypt by setting the flags for certificatr type and letecrypt email in my config without success. When vidu boots up it correctly identifies that letsecrypt is selected but still serves up the Vidu signed certificate instead of anything from LetEncrypt.

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [November 18, 2020, 1:52pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/2 "2020-11-18T13:52:33Z")

</div>

Hi @jamesroche

Please check these links and try to follow these instructions:

1. Installation of owncert: [https://docs.openvidu.io/en/latest/deployment/deploying-on-premises/#3-custom-certificate-commercial-ca](https://docs.openvidu.io/en/latest/deployment/deploying-on-premises/#3-custom-certificate-commercial-ca)
2. Troubleshooting: [https://docs.openvidu.io/en/latest/troubleshooting/#15-my-commercial-certificate-is-not-working-what-can-i-do](https://docs.openvidu.io/en/latest/troubleshooting/#15-my-commercial-certificate-is-not-working-what-can-i-do)

Also what version are you deploying, 2.16.0?

---

<div class="post-metadata">

**Author:** ![jamesroche](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jamesroche](https://openvidu.discourse.group/u/jamesroche)\
**Post date:** [November 18, 2020, 2:01pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/3 "2020-11-18T14:01:56Z")

</div>

Yes 2.16

I have been trying to follow that SSL guide but I have only a certificate.pfx to work with and I am not the best with OPEN SSL. I have with the help of Google converted it over but my private key has RSA in the header which si different to the troubleshooting link you sent over

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [November 18, 2020, 2:12pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/4 "2020-11-18T14:12:15Z")

</div>

So, you have a certificate.pfx (I suppose that this is your public certificate) and a private key with RSA header correct?

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [November 18, 2020, 2:17pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/5 "2020-11-18T14:17:57Z")

</div>

1. Try to get the private key with this command:

```auto
openssl pkcs12 -in certificate.pfx -nocerts -out key.pem

```

1. And the public one with this one:

```auto
openssl pkcs12 -in certificate.pfx -clcerts -nokeys -out cert.pem

```

1. Rename both files:  
`key.pem -> certificate.key`  
`cert.pem -> certificate.cert`

2. After that, check that both files follow this format:  
[https://docs.openvidu.io/en/latest/troubleshooting/#15-my-commercial-certificate-is-not-working-what-can-i-do](https://docs.openvidu.io/en/latest/troubleshooting/#15-my-commercial-certificate-is-not-working-what-can-i-do)

3. Then copy them to `/opt/openvidu/owncert` and restart openvidu with sudo:

```auto
cd /opt/openvidu
./openvidu restart

```

Hope this helps,

Regards,  
Carlos

---

<div class="post-metadata">

**Author:** ![jamesroche](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jamesroche](https://openvidu.discourse.group/u/jamesroche)\
**Post date:** [November 18, 2020, 2:24pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/6 "2020-11-18T14:24:58Z")

</div>

I followed your process and i am seeing some stuff like

Bag Attributes  
friendlyName: {590ff44c-ccaf-4bfc-ba58-9f95d532caf1}  
localKeyID: 54 69 6D 65 20 31 35 39 35 35 30 33 36 32 30 36 35 38  
Microsoft CSP Name: Microsoft Enhanced Cryptographic Provider v1.0  
Microsoft Local Key set:

in between 2 certificates in my certificate.cert

In my certificate.key i only see

Bag Attributes  
friendlyName: {f8153e1e-45ab-4459-acc6-4c894091b084}  
localKeyID: 01 00 00 00  
Microsoft CSP Name: Microsoft RSA SChannel Cryptographic Provider  
Microsoft Local Key set:   
Key Attributes  
X509v3 Key Usage: 10  
Bag Attributes  
friendlyName: {590ff44c-ccaf-4bfc-ba58-9f95d532caf1}  
localKeyID: 54 69 6D 65 20 31 35 39 35 35 30 33 36 32 30 36 35 38  
Microsoft CSP Name: Microsoft Enhanced Cryptographic Provider v1.0  
Microsoft Local Key set:   
Key Attributes:

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [November 18, 2020, 2:26pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/7 "2020-11-18T14:26:07Z")

</div>

Delete this stuff if you want, just make sure that this format is correct in the final files: [https://docs.openvidu.io/en/latest/troubleshooting/#15-my-commercial-certificate-is-not-working-what-can-i-do](https://docs.openvidu.io/en/latest/troubleshooting/#15-my-commercial-certificate-is-not-working-what-can-i-do)

Two certificates is correct. This is a chain.

---

<div class="post-metadata">

**Author:** ![jamesroche](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jamesroche](https://openvidu.discourse.group/u/jamesroche)\
**Post date:** [November 18, 2020, 2:36pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/8 "2020-11-18T14:36:17Z")

</div>

I have completed as per instructions and the formats match the outputs in the help doc but when i startup Vidu i am still getting the vidu signed certiciate [openvidu@gmail.com](mailto:openvidu@gmail.com) etc.

How can i check for errors or outputs around SSL? I am not entirely convinced its finding the certificates

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [November 18, 2020, 2:48pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/9 "2020-11-18T14:48:02Z")

</div>

Can you show me the output of:

```auto
sudo su
cd /opt/openvidu
./openvidu version

```

Also check the nginx logs with:

```auto
sudo su
cd /opt/openvidu
docker-compose logs nginx

```

---

<div class="post-metadata">

**Author:** ![jamesroche](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jamesroche](https://openvidu.discourse.group/u/jamesroche)\
**Post date:** [November 18, 2020, 2:50pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/10 "2020-11-18T14:50:22Z")

</div>

I don’t have anything in opt/openvidu. I am running the jar file from my home directory. Its also reading my .env from /home/user/.env.

Is this workable? I am not using docker

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [November 18, 2020, 2:52pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/11 "2020-11-18T14:52:27Z")

</div>

No sorry. It’s not impossible to run OpenVidu only in a jar file, but you need to follow these instructions to have support from our side:

> **[OpenVidu Docs](https://docs.openvidu.io/en/2.16.0/deployment/deploying-on-premises/)**

In this way we can help in a more standardized and uniform way to people trying to deploy OpenVidu

So you need to use this official instructions and use Docker and Docker Compose.

BTW if you will do that you need to remove all previous services (nginx, openvidu, redis, kurento-media-server) from your system.

Regards,  
Carlos

---

<div class="post-metadata">

**Author:** ![jamesroche](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jamesroche](https://openvidu.discourse.group/u/jamesroche)\
**Post date:** [November 18, 2020, 2:55pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/12 "2020-11-18T14:55:02Z")

</div>

This makes sense. I had been following the upgrade guide. I will folow this now

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [November 18, 2020, 2:57pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/13 "2020-11-18T14:57:39Z")

</div>

Nice!

Regards,  
Carlos

---

<div class="post-metadata">

**Author:** ![jamesroche](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jamesroche](https://openvidu.discourse.group/u/jamesroche)\
**Post date:** [November 18, 2020, 6:06pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/14 "2020-11-18T18:06:50Z")

</div>

This really helped out buddy thanks. Quick question though, now that I am setup and working again how to stop the Openvidu test app from shwoing up at the root url? theres a one click video conferencing popup i get now.

---

<div class="post-metadata">

**Author:** ![cruizba](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/cruizba/32/18_2.png) [@cruizba](https://openvidu.discourse.group/u/cruizba)\
**Post date:** [November 18, 2020, 6:46pm UTC](https://openvidu.discourse.group/t/ssl-issues-on-ubuntu-deployment-after-upgrade/2281/15 "2020-11-18T18:46:28Z")

</div>

Glad to hear that 🙂  
You need to:

1. Edit this file `/opt/openvidu/docker-compose.yml` and replace:

```auto
WITH_APP=true

```

to

```auto
WITH_APP=false

```

in nginx service.

1. Delete the file `/opt/openvidu/docker-compose.override.yml`

Best Regards,  
Carlos
