HTTPS
Serve Nifty over HTTPS with your own certificate or a free one from Let's Encrypt.
On this page
Nifty can serve HTTPS itself, one way at a time. Pick the one that fits:
| Way | Use it when |
|---|---|
| Let's Encrypt | The internet reaches this machine at your domain |
| Let's Encrypt over Cloudflare DNS | It doesn't (a home or office server), and the domain's DNS is on Cloudflare |
| Certificate files | You already have a certificate, from certbot or elsewhere |
| Tailscale | Only your own devices need to reach it |
| Behind a proxy | Caddy, nginx or similar already handles HTTPS |
install.sh sets up any of these for you (Install on Linux). The settings below go in
/etc/nifty.env; restart Nifty after changing them (sudo systemctl restart nifty).
Plain http:// works off this machine, but your password then crosses the network unencrypted, and Nifty warns in its
log as it starts.
Let's Encrypt
NIFTY_ORIGIN=https://notes.example.com
NIFTY_LISTEN=:443
NIFTY_ACME=tls
[email protected] # optional
- The domain's DNS points at this machine, and the internet reaches it on port 443 or 80.
- Nifty gets the certificate on the first visit, so that one takes a few seconds. It renews 30 days before expiry.
- It redirects
http://on port 80 to HTTPS.
Let's Encrypt over Cloudflare DNS
For a machine the internet can't reach, such as a home server or one on your tailnet. Nifty proves the domain is yours by adding a DNS record through Cloudflare's API.
In Cloudflare, open My Profile → API Tokens and create a token with Zone → DNS → Edit on this domain's zone only.
Point the domain at this machine's local or tailnet address, so your devices find it.
Add the settings, then restart Nifty:
NIFTY_ORIGIN=https://notes.example.com NIFTY_LISTEN=:443 NIFTY_ACME=cloudflare NIFTY_CLOUDFLARE_API_TOKEN=…
The certificate usually arrives within two minutes of starting. The token works only from the environment, never as a
flag: keep /etc/nifty.env as install.sh writes it, root:nifty, mode 640.
Certificate files
NIFTY_ORIGIN=https://notes.example.com
NIFTY_LISTEN=:443
NIFTY_TLS_CERT=/etc/ssl/nifty/fullchain.pem
NIFTY_TLS_KEY=/etc/ssl/nifty/privkey.pem
- PEM files: the full chain, and its private key. Nifty won't start if they don't match, have expired or don't cover the origin's host.
- Nifty re-reads them within a minute of a change, so renewals need no restart. If a new pair doesn't load, it keeps the old one and logs why.
- The
niftyuser must be able to read them, and they can't live under/homeor/root. For certbot's files:sudo setfacl -m u:nifty:r <file>, plusu:nifty:xon each directory above it.
Ports 443 and 80
Ports below 1024 need a systemd drop-in. install.sh adds it; to add it yourself, create
/etc/systemd/system/nifty.service.d/ports.conf:
[Service]
AmbientCapabilities=CAP_NET_BIND_SERVICE
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
Then sudo systemctl daemon-reload && sudo systemctl restart nifty. To redirect from somewhere other than port 80, or
not at all, set NIFTY_REDIRECT_HTTP (Configuration).
Try it first
Let's Encrypt limits how often it issues certificates. While you experiment, use its staging server (browsers won't trust the certificate):
NIFTY_ACME_DIRECTORY=https://acme-staging-v02.api.letsencrypt.org/directory
When it works, remove that line and restart. Nifty then gets a real certificate.
If no certificate comes
Every step is in the log, as lines starting tls::
journalctl -u nifty | grep tls:
A failure logs Let's Encrypt's reason, the fix where it's known, and when Nifty tries again (an hour later). Fix the cause and restart to try at once. Nifty warns in the log when a certificate has less than 14 days left.