<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://wiki.avobjects.com/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://wiki.avobjects.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Dkn</id>
		<title>AVObjects Knowledge Base - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="http://wiki.avobjects.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Dkn"/>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Special:Contributions/Dkn"/>
		<updated>2026-08-25T03:52:07Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.18.2</generator>

	<entry>
		<id>http://wiki.avobjects.com/MultiMedia_Components_%26_DirectShow_Filters</id>
		<title>MultiMedia Components &amp; DirectShow Filters</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/MultiMedia_Components_%26_DirectShow_Filters"/>
				<updated>2026-07-28T10:30:10Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to AVObjects Knowledge Base!&lt;br /&gt;
&lt;br /&gt;
We are a group of digital media experts focused at providing customers with innovative solutions that address their needs. In this wiki we try to accomodate our expertise, more or less centered around our products.&lt;br /&gt;
&lt;br /&gt;
* [[:Category:Products|Products]]&lt;br /&gt;
* [[:Category:Release Notes|Release Notes]]&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;!--* [[:Category:DirectShow Filters|DirectShow Filters]]--&amp;gt;&lt;br /&gt;
* [[:Category:Multimedia Components|Multimedia Development Components]]&lt;br /&gt;
* [[:Category:Software Development Kits|Software Development Kits]]&lt;br /&gt;
* [[:Category:Plugins|Plugins]]&lt;br /&gt;
* [[:Category:Applications|Applications]]&lt;br /&gt;
* [[:Category:Company|Company]]&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* [[Audio &amp;amp; Video Software Development Services]]&lt;br /&gt;
* [[Web Media Development]]&lt;br /&gt;
&lt;br /&gt;
* [[Media Foundation Technology]]&lt;br /&gt;
* [[QuickTime Development]]&lt;br /&gt;
* [[Silverlight|Silverlight Technology]]--&amp;gt;&lt;br /&gt;
* [[:Category:AVObjects Library|AVObjects Library]]&lt;br /&gt;
* [[:Category:Sales|Sales]]&lt;br /&gt;
* [[Technical Support]]&lt;br /&gt;
* [http://www.avobjects.com AVObjects Web Site]&lt;br /&gt;
* [[Download|Products downloads]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
==New==&lt;br /&gt;
&lt;br /&gt;
* [[:Category:Industries|Industries]]&lt;br /&gt;
* [[:Category:FAQs|FAQs]]&lt;br /&gt;
* [[:Category:Release Notes|Release Notes]]&lt;br /&gt;
* [[Development Roadmap]]&lt;br /&gt;
* [[:Category:Developer Info|Developer Info]]&lt;br /&gt;
* [[Multimedia Components Overview]]&lt;br /&gt;
* [[Multimedia Component SDK Comparison]]&lt;br /&gt;
* [[What Is a Single Application]]--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Hints==&lt;br /&gt;
&lt;br /&gt;
* [[Problem Description Guidelines]]&lt;br /&gt;
&amp;lt;!--* [[Redistribution Guidelines]]--&amp;gt;&lt;br /&gt;
* [[Spy &amp;amp; Log]]&lt;br /&gt;
* [[:Category:Helpers|Helpers]]&lt;br /&gt;
* [[AVObjects FTP]]&lt;br /&gt;
&lt;br /&gt;
==Links==&lt;br /&gt;
&lt;br /&gt;
* [http://blog.avobjects.com AVObjects Blog]&lt;br /&gt;
__NOEDITSECTION__&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/MultiMedia_Components_%26_DirectShow_Filters</id>
		<title>MultiMedia Components &amp; DirectShow Filters</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/MultiMedia_Components_%26_DirectShow_Filters"/>
				<updated>2026-07-28T10:29:41Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to AVObjects Knowledge Base!&lt;br /&gt;
&lt;br /&gt;
We are a group of digital media experts focused at providing customers with innovative solutions that address their needs. In this wiki we try to accomodate our expertise, more or less centered around our products.&lt;br /&gt;
&lt;br /&gt;
* [[:Category:Products|Products]]&lt;br /&gt;
* [[:Category:Release Notes|Release Notes]]&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;!--* [[:Category:DirectShow Filters|DirectShow Filters]]--&amp;gt;&lt;br /&gt;
* [[:Category:Multimedia Components|Multimedia Development Components]]&lt;br /&gt;
* [[:Category:Software Development Kits|Software Development Kits]]&lt;br /&gt;
* [[:Category:Plugins|Plugins]]&lt;br /&gt;
* [[:Category:Applications|Applications]]&lt;br /&gt;
* [[:Category:Company|Company]]&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* [[Audio &amp;amp; Video Software Development Services]]&lt;br /&gt;
* [[Web Media Development]]&lt;br /&gt;
&lt;br /&gt;
* [[Media Foundation Technology]]&lt;br /&gt;
* [[QuickTime Development]]&lt;br /&gt;
* [[Silverlight|Silverlight Technology]]--&amp;gt;&lt;br /&gt;
* [[:Category:AVObjects Library|AVObjects Library]]&lt;br /&gt;
* [[:Category:Sales|Sales]]&lt;br /&gt;
* [[Technical Support]]&lt;br /&gt;
* [http://www.avobjects.com AVObjects Web Site]&lt;br /&gt;
* [[Download|Products downloads]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
==New==&lt;br /&gt;
&lt;br /&gt;
* [[:Category:Industries|Industries]]&lt;br /&gt;
* [[:Category:FAQs|FAQs]]&lt;br /&gt;
* [[:Category:Release Notes|Release Notes]]&lt;br /&gt;
* [[Development Roadmap]]&lt;br /&gt;
* [[:Category:Developer Info|Developer Info]]&lt;br /&gt;
* [[Multimedia Components Overview]]&lt;br /&gt;
* [[Multimedia Component SDK Comparison]]&lt;br /&gt;
* [[What Is a Single Application]]--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Hints==&lt;br /&gt;
&lt;br /&gt;
* [[:Category:Helpers|Helpers]]&lt;br /&gt;
* [[Problem Description Guidelines]]&lt;br /&gt;
&amp;lt;!--* [[Redistribution Guidelines]]--&amp;gt;&lt;br /&gt;
* [[Spy &amp;amp; Log]]&lt;br /&gt;
* [[AVObjects FTP]]&lt;br /&gt;
&lt;br /&gt;
==Links==&lt;br /&gt;
&lt;br /&gt;
* [http://blog.avobjects.com AVObjects Blog]&lt;br /&gt;
__NOEDITSECTION__&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Category:Helpers</id>
		<title>Category:Helpers</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Category:Helpers"/>
				<updated>2026-07-28T10:27:34Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: Created page with &amp;quot;This category lists all helper documents.&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This category lists all helper documents.&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:24:12Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Using HTTPS--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/webrtc_server/using_https.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at &lt;br /&gt;
[mailto:support@avobjects.com support@avobjects.com] &lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:23:50Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Using HTTPS--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/webrtc_server/using_https.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at &lt;br /&gt;
[mailto:support@avobjects.com support@avobjects.com] &lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:22:40Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Using HTTPS--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/webrtc_server/using_https.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at &lt;br /&gt;
[mailto:support@avobjects.com support@avobjects.com] &lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:20:59Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Using HTTPS--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/webrtc_server/using_https.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at &lt;br /&gt;
[mailto:support@avobjects.com support@avobjects.com] &lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:15:21Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Using HTTPS--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/webrtc_server/using_https.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at &lt;br /&gt;
[mailto:support@avobjects.com support@avobjects.com] &lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:14:33Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Using HTTPS--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at &lt;br /&gt;
[mailto:support@avobjects.com support@avobjects.com] &lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:08:55Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at &lt;br /&gt;
[mailto:support@avobjects.com support@avobjects.com] &lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:07:34Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at mailto:support@avobjects.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:06:56Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at [support@avobjects.com|mailto:support@avobjects.com]&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:06:07Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at mailto:support@avobjects.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:04:56Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at {{Contact Support}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:04:36Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at s{{Contact Support}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:04:01Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at support@avobjects.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:03:13Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
&amp;lt;b&amp;gt;certhash:&amp;lt;/b&amp;gt; The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
* Select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
* double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
&amp;lt;b&amp;gt;appid:&amp;lt;/b&amp;gt; You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;certstorename:&amp;lt;/b&amp;gt; The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
==Using HTTPS==&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at support@avobjects.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T10:00:08Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
certhash: The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
&amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
&amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
&amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
&amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
&amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
appid: You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
certstorename: The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
Using HTTPS&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at support@avobjects.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:59:34Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&amp;lt;br&amp;gt;&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
certhash: The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
&amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
&amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
&amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
&amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
&amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
appid: You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
certstorename: The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
Using HTTPS&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at support@avobjects.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:59:12Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
certhash: The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
&amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
&amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
&amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
&amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
&amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
appid: You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
certstorename: The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
Using HTTPS&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at support@avobjects.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:58:20Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Installing certificates==&lt;br /&gt;
Both certificates are installed using the Microsoft Management Console:&lt;br /&gt;
&lt;br /&gt;
1). Open MMC&lt;br /&gt;
&lt;br /&gt;
* Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
* Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (default) -&amp;gt; press &amp;quot;Finish&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot;&lt;br /&gt;
* &amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Adding CA certificate rootCA.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;rootCA.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;rootCA.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter CA certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Trusted Root Certification Authorities&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Trusted Root Certification Authorities&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Adding work certificate cert.my+4.pfx&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot; -&amp;gt; right mouse button -&amp;gt; &amp;quot;All Tasks&amp;quot; -&amp;gt; &amp;quot;Import...&amp;quot; -&amp;gt; &amp;quot;Certificate Import Wizard&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;File to import&amp;quot; dialog&lt;br /&gt;
* &amp;quot;File to import&amp;quot; dialog -&amp;gt; put &amp;quot;cert.my+4.pfx&amp;quot; with path to &amp;quot;File Name:&amp;quot; or use &amp;quot;Browse...&amp;quot; to select &amp;quot;cert.my+4.pfx&amp;quot; file (use the drop-down list to the right of the &amp;quot;File name:&amp;quot; field to select .pfx file) -&amp;gt; press &amp;quot;Next&amp;quot; -&amp;gt; &amp;quot;Private key protection&amp;quot; dialog&lt;br /&gt;
* &amp;quot;Private key protection&amp;quot; -&amp;gt; enter work certificate password from step 1d). to &amp;quot;Password&amp;quot; -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Certificate Store&amp;quot; -&amp;gt; select &amp;quot;Place all certificates ...&amp;quot; : &amp;quot;Personal&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Next&amp;quot;&lt;br /&gt;
* &amp;quot;Completing the Certificate Import Wizard&amp;quot; -&amp;gt; press &amp;quot;Finish&amp;quot;&lt;br /&gt;
* If all is OK: box with &amp;quot;The import was successful&amp;quot; will be shown -&amp;gt; press &amp;quot;OK&amp;quot;&lt;br /&gt;
Now you can see certificate Issued To &amp;quot;&amp;lt;user name&amp;gt;\...&amp;quot; Issued By &amp;quot;mkcert &amp;lt;user name&amp;gt;\...&amp;quot; in &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Binding certificate==&lt;br /&gt;
To use a working certificate (cert.my+4.pfx), it must be bound to an address:port.&lt;br /&gt;
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-http&lt;br /&gt;
&lt;br /&gt;
Adds SSL certificate binding for a specified IP address and port, along with corresponding client certificate policies, to securely manage HTTPS connections for the HTTP Service:&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http add sslcert ipport=127.0.0.1:50000 certhash=0123456789abcdef0123456789abcdef01234567 appid={00112233-4455-6677-8899-AABBCCDDEEFF}&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shows a list of SSL server certificate bindings for the specified ipport:&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http show sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes SSL server certificate bindings for the specified ipport:&lt;br /&gt;
  &amp;lt;b&amp;gt;netsh http delete sslcert ipport=127.0.0.1:50000&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Options.===&lt;br /&gt;
certhash: The certificate hash (often represented as a thumbprint) of the SSL certificate to be bound. It can be obtained (for example) from mmc (Microsoft Management Console):&lt;br /&gt;
&lt;br /&gt;
Windows Start -&amp;gt; Run -&amp;gt; mmc -&amp;gt; OK -&amp;gt; Yes&lt;br /&gt;
Microsoft Management Console: Menu &amp;quot;File&amp;quot; -&amp;gt; &amp;quot;Add/Remove Snap-in...&amp;quot; -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
&amp;quot;Add or Remove Snap-ins&amp;quot; dialog: select &amp;quot;Certrificates&amp;quot; -&amp;gt; press &amp;quot;Add&amp;quot; -&amp;gt; &amp;quot;Certificates snap-in&amp;quot; dialog&lt;br /&gt;
&amp;quot;Certificates snap-in&amp;quot; dialog : select &amp;quot;Computer account&amp;quot; -&amp;gt; press &amp;quot;Next &amp;gt;&amp;quot; button -&amp;gt; &amp;quot;Select Computer&amp;quot; dialog&lt;br /&gt;
&amp;quot;Select Computer&amp;quot; dialog: select &amp;quot;Local computer ...&amp;quot; (selected by default) -&amp;gt; press &amp;quot;Finish&amp;quot; button -&amp;gt; &amp;quot;Add or Remove Snap-ins&amp;quot; dialog&lt;br /&gt;
&amp;quot;Add or Remove Snap-ins&amp;quot; dialog: press &amp;quot;OK&amp;quot; button&lt;br /&gt;
select &amp;quot;Certificates (Local Computer)&amp;quot; -&amp;gt; &amp;quot;Personal&amp;quot; -&amp;gt; &amp;quot;Certificates&amp;quot;&lt;br /&gt;
double left mouse click on wanted certificate -&amp;gt; &amp;quot;Certificate&amp;quot; dialog&lt;br /&gt;
&amp;quot;Certificate&amp;quot; dialog -&amp;gt; tab &amp;quot;Details&amp;quot; -&amp;gt; select &amp;quot;Thumbprint&amp;quot; field -&amp;gt; copy certhash&lt;br /&gt;
appid: You can use any GUID as the appid (is this an atavism? It was tested with GUID_NULL - everything works fine, no issues found).&lt;br /&gt;
&lt;br /&gt;
certstorename: The name of the certificate store where the SSL certificate is located, default is &amp;quot;MY&amp;quot; (&amp;quot;Personal&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
Using HTTPS&lt;br /&gt;
Now you can test the WRTP server's operation over HTTPS on your local computer, for example: https://127.0.0.1:50000&lt;br /&gt;
If you want to test WebRTC/RTP server playback from another computer on your local network, you should install the used CA certificate (rootCA.pfx) on that computer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any notes, comments or suggestions about the information on this page, please contact us at support@avobjects.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:54:35Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:53:24Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:52:32Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;b/&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;i/&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:51:22Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;i/&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;b/&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;i/&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:50:12Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;/i&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;i/&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;/i&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;/i&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;/b&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:48:25Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;br&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;i/&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;i/&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;b/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:47:49Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&amp;lt;br&amp;gt;&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;b/&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;i/&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;i/&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;b/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:46:36Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  &amp;lt;b&amp;gt;rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&amp;lt;b/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  &amp;lt;b&amp;gt;cd &amp;lt;folder with certificates&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX rootCA.cer rootCA.pfx&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;i/&amp;gt;&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  &amp;lt;b&amp;gt;certutil -MergePFX cert.my+4.cer cert.my+4.pfx&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Confirm new password:&amp;lt;i/&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;******&amp;lt;Enter&amp;gt;&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; CertUtil: -MergePFX command completed successfully.&amp;lt;i/&amp;gt;&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;b&amp;gt;&amp;lt;folder with certificates&amp;gt;&amp;lt;b/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:43:23Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:42:53Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new certificate valid for the following names&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:41:40Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&amp;lt;br&amp;gt;&lt;br /&gt;
NOTE. IP address &amp;lt;b&amp;gt;192.168.1.999&amp;lt;/b&amp;gt; is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:40:07Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:39:35Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:39:21Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:38:52Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; The local CA is now installed in the system trust store!&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:38:19Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;lt;i&amp;gt;&amp;gt; Created a new local CA&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press &amp;lt;b&amp;gt;Yes&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
  &amp;gt; The local CA is now installed in the system trust store!&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:37:06Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;/b&amp;gt;&lt;br /&gt;
  &amp;gt; Created a new local CA&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press Yes&lt;br /&gt;
  &amp;gt; The local CA is now installed in the system trust store!&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:36:46Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;b\&amp;gt;&lt;br /&gt;
  &amp;gt; Created a new local CA&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press Yes&lt;br /&gt;
  &amp;gt; The local CA is now installed in the system trust store!&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:36:26Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;b/&amp;gt;&lt;br /&gt;
  &amp;gt; Created a new local CA&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press Yes&lt;br /&gt;
  &amp;gt; The local CA is now installed in the system trust store!&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:36:02Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  &amp;lt;b&amp;gt;mkcert -install&amp;lt;\b&amp;gt;&lt;br /&gt;
  &amp;gt; Created a new local CA&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press Yes&lt;br /&gt;
  &amp;gt; The local CA is now installed in the system trust store!&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:35:07Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  mkcert -install&lt;br /&gt;
  &amp;gt; Created a new local CA&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press Yes&lt;br /&gt;
  &amp;gt; The local CA is now installed in the system trust store!&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:34:57Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  mkcert -install&lt;br /&gt;
  &amp;gt; Created a new local CA&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press Yes&lt;br /&gt;
  &amp;gt; The local CA is now installed in the system trust store!&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:33:14Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&amp;lt;br&amp;gt;Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  mkcert -install&lt;br /&gt;
  &amp;gt; Created a new local CA&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press Yes&lt;br /&gt;
  &amp;gt; The local CA is now installed in the system trust store!&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:32:12Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
==Creating certificates==&lt;br /&gt;
To create 2 debug certificates for testing the HTTPS protocol, you need to do the following:&lt;br /&gt;
&lt;br /&gt;
1). Installing mkcert.exe&lt;br /&gt;
&lt;br /&gt;
* open https://github.com/FiloSottile/mkcert/releases&lt;br /&gt;
* download the mkcert-v1.4.4-windows-amd64.exe file to the &amp;quot;C:\Program Files\mkcert&amp;quot; folder (create this folder) and rename it to mkcert.exe.&lt;br /&gt;
* add &amp;quot;C:\Program Files\mkcert&amp;quot; to PATH (system variables):&lt;br /&gt;
Settings -&amp;gt; System -&amp;gt; About -&amp;gt; Advanced system settings -&amp;gt; Enviroment variables -&amp;gt; System variables\Path: press &amp;quot;Edit...&amp;quot; -&amp;gt; Press &amp;quot;New&amp;quot; -&amp;gt; put &amp;quot;C:\Program Files\mkcert&amp;quot; -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; press OK -&amp;gt; Close Settings.About&lt;br /&gt;
&lt;br /&gt;
2). Creating CA certificate (&amp;lt;user name&amp;gt; is name of curent user).&lt;br /&gt;
&lt;br /&gt;
* remove old CA certificate from &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder&lt;br /&gt;
* open Windows console (command prompt or Windows terminal) with administrator rights&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter:&lt;br /&gt;
  mkcert -install&lt;br /&gt;
  &amp;gt; Created a new local CA&lt;br /&gt;
  In &amp;quot;Security Warning&amp;quot; Dialog : press Yes&lt;br /&gt;
  &amp;gt; The local CA is now installed in the system trust store!&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;rootCA.pem&amp;quot; and &amp;quot;rootCA-key.pem&amp;quot; should have been created in the &amp;quot;C:\Users\&amp;lt;user name&amp;gt;\AppData\Local\mkcert&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
3). Creating work certificate cert.my for 4 names.&lt;br /&gt;
NOTE. IP address 192.168.1.999 is used as server IP address, please change it to your real IP address.&lt;br /&gt;
&lt;br /&gt;
* in the console window (header &amp;quot;Administrator: Command&amp;quot;) enter&lt;br /&gt;
  mkcert cert.my localhost 127.0.0.1 ::1 192.168.1.999&lt;br /&gt;
  &amp;gt; Created a new certificate valid for the following names&lt;br /&gt;
  &amp;gt; - &amp;quot;cert.my&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;localhost&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;127.0.0.1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;::1&amp;quot;&lt;br /&gt;
  &amp;gt; - &amp;quot;192.168.1.999&amp;quot;&lt;br /&gt;
  &amp;gt; The certificate is at &amp;quot;./cert.my+4.pem&amp;quot; and the key at &amp;quot;./cert.my+4-key.pem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* The files &amp;quot;cert.my+4.pem&amp;quot; and &amp;quot;cert.my+4-key.pem&amp;quot; should have been created in the &amp;quot;C:\Windows\System32&amp;quot; folder. Move them to some folder where you will store your certificates.&lt;br /&gt;
&lt;br /&gt;
4). Convert .pem files to .pfx files using the certutil tool.&lt;br /&gt;
&lt;br /&gt;
* rename your .pem files:&lt;br /&gt;
  rootCA.pem -&amp;gt; rootCA.cer&lt;br /&gt;
  rootCA-key.pem -&amp;gt; rootCA.key&lt;br /&gt;
  cert.my+4.pem -&amp;gt; cert.my+4.cer&lt;br /&gt;
  cert.my+4-key.pem -&amp;gt; cert.my+4.key&lt;br /&gt;
&lt;br /&gt;
* In the console window (header &amp;quot;Administrator: Command&amp;quot;), go to the folder containing the certificates:&lt;br /&gt;
  cd &amp;lt;folder with certificates&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* convert rootCA.cer and rootCA.key files to rootCA.pfx&lt;br /&gt;
  certutil -MergePFX rootCA.cer rootCA.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file rootCA.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;rootCA.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* convert cert.my+4.cer and cert.my+4.key files to cert.my+4.pfx&lt;br /&gt;
  certutil -MergePFX cert.my+4.cer cert.my+4.pfx&lt;br /&gt;
  &amp;gt; Signature test passed&lt;br /&gt;
  &amp;gt; Enter new password for output file cert.my+4.pfx:&lt;br /&gt;
  &amp;gt; Enter new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; Confirm new password:&lt;br /&gt;
  ******&amp;lt;Enter&amp;gt;&lt;br /&gt;
  &amp;gt; CertUtil: -MergePFX command completed successfully.&lt;br /&gt;
The file &amp;quot;cert.my+4.pfx&amp;quot; should have been created in the &amp;lt;folder with certificates&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:29:48Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
==Steps required to use the HTTPS protocol.==&lt;br /&gt;
Before you can start using the HTTPS protocol to communicate with a WRTP server, you need to create, install, and bind certificates.&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Using_HTTPS</id>
		<title>Using HTTPS</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Using_HTTPS"/>
				<updated>2026-07-28T09:27:53Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: Created page with &amp;quot;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt; &amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt; &amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt; {{This|products/helpers/webrtc_...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--TITLE:WebRTC/RTP Server: Helpers--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:Hints for using HTTPS with WebRTC/RTP Server.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP http https --&amp;gt;&lt;br /&gt;
{{This|products/helpers/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Helpers]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/WebRTC/RTP_Server</id>
		<title>WebRTC/RTP Server</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/WebRTC/RTP_Server"/>
				<updated>2026-07-28T09:21:01Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--RM_ID:143--&amp;gt;&lt;br /&gt;
&amp;lt;!--TITLE:WebRTC/RTP Server DirectShow filter--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:DirectShow Filter for streaming media in the network.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:WebRTC RTP DirectShow HTTP streaming H264 Opus --&amp;gt;&lt;br /&gt;
{{This|products/network_filters/webrtc_server.html}}&lt;br /&gt;
&lt;br /&gt;
{{WebRTC/RTP Server: Description}}&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
WebRTC/RTP Server is a DirectShow Filter for sending media streams from the graph to the network. It gets encoded video or audio streams and send them by the network to peers wia WebRTC compatible protocols. The filter performs a renderer function and must be placed as a sink filter in the graph (the last filter in the graph chain).&lt;br /&gt;
&lt;br /&gt;
==Features==&lt;br /&gt;
&lt;br /&gt;
* Compatible with most popular browsers such as Google Chrome, Safari, Microsoft Edge&lt;br /&gt;
* Compatibility with most mobile and desktop devices running on operating systems Windows, iOS, MacOS, Android.&lt;br /&gt;
* Supports the HTTPS protocol. For more information, see [[Using HTTPS]]&lt;br /&gt;
* Supports secure connections using SRTP and DTLS. &lt;br /&gt;
* Supports video encoders H.264/AVC, VP8, VP9.&lt;br /&gt;
* Supports audio encoders Opus, PCMA(G.711a), PCMU(G.711u).&lt;br /&gt;
* Contains built-in HTTP signaling server for exchanging SDP information with WebRTC peers.&lt;br /&gt;
* Received streams can be displayed in browsers without Adobe Flash object.&lt;br /&gt;
&lt;br /&gt;
==Supported Formats==&lt;br /&gt;
&lt;br /&gt;
* H.264/AVC video&lt;br /&gt;
* VP8 video&lt;br /&gt;
* VP9 video&lt;br /&gt;
* Opus audio (48 KHz, 16 bit, 1 or 2 channels)&lt;br /&gt;
* L16 PCM (44.1 KHz, 16 bit, 1 or 2 channels)&lt;br /&gt;
* a-Law/PCMA/G.711a audio (8 KHz, 8 bit, 1 channel)&lt;br /&gt;
* u-Law/PCMU/G.711u audio (8 KHz, 8 bit, 1 channel)&lt;br /&gt;
&lt;br /&gt;
==Supported Standards==&lt;br /&gt;
&lt;br /&gt;
* [https://www.w3.org/TR/webrtc W3C(CR) 2009-06-21]:  WebRTC 1.0: Real-time Communication Between Browsers&lt;br /&gt;
* [http://tools.ietf.org/html/rfc3550 IETF RFC 3550(2003)]: RTP: A Transport Protocol for Real-Time Applications&lt;br /&gt;
* [http://tools.ietf.org/html/rfc3551 IETF RFC 3551(2003)]: RTP Profile for Audio and Video Conferences with Minimal Control&lt;br /&gt;
* [http://tools.ietf.org/html/rfc3711 IETF RFC 3711(2004)]: The Secure Real-time Transport Protocol (SRTP)&lt;br /&gt;
* [http://tools.ietf.org/html/rfc4566 IETF RFC 4566(2006)]: SDP: Session Description Protocol&lt;br /&gt;
* [http://tools.ietf.org/html/rfc5389 IETF RFC 5389(2008)]: Session Traversal Utilities for NAT (STUN) &lt;br /&gt;
* [http://tools.ietf.org/html/rfc5766 IETF RFC 5766(2010)]: Traversal Using Relays around NAT (TURN): Relay Extensions to Session Traversal Utilities for NAT (STUN)&lt;br /&gt;
* [http://tools.ietf.org/html/rfc6184 IETF RFC 6184(2011)]: RTP Payload Format for H.264 Video &lt;br /&gt;
* [http://tools.ietf.org/html/rfc6347 IETF RFC 6347(2012)]: Datagram Transport Layer Security Version 1.2&lt;br /&gt;
* [http://tools.ietf.org/html/rfc7231 IETF RFC 7231(2014)]: Hypertext Transfer Protocol (HTTP/1.1): Semantics and Content&lt;br /&gt;
* [http://tools.ietf.org/html/rfc7587 IETF RFC 7587(2015)]: RTP Payload Format for the Opus Speech and Audio Codec&lt;br /&gt;
* [http://tools.ietf.org/html/rfc7741 IETF RFC 7741(2016)]: RTP Payload Format for VP8 Video&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
&lt;br /&gt;
* [[WebRTC/RTP Server: Release Notes]]&lt;br /&gt;
* [[WebRTC/RTP Server: Technical Specs]]&lt;br /&gt;
&lt;br /&gt;
==You Might Also Need==&lt;br /&gt;
&lt;br /&gt;
* {{LinkDescription|QuickSync Encoder}}&lt;br /&gt;
* {{LinkDescription|Opus Encoder}}&lt;br /&gt;
* {{LinkDescription|Video Generator}}&lt;br /&gt;
&lt;br /&gt;
==Related Products==&lt;br /&gt;
&lt;br /&gt;
* {{LinkDescription|AAC Encoder}}&lt;br /&gt;
* {{LinkDescription|Opus Encoder}}&lt;br /&gt;
* {{LinkDescription|RTMP Server}}&lt;br /&gt;
* {{LinkDescription|H.264/AVC Decoder}}&lt;br /&gt;
* {{LinkDescription|Audio Mixer}} It can be useful when working with third-party audio codecs&lt;br /&gt;
&lt;br /&gt;
===Action Items===&lt;br /&gt;
&lt;br /&gt;
* {{WebRTC/RTP Server: Download}}&lt;br /&gt;
* {{Contact Support}}&lt;br /&gt;
* {{Place Order!}}&lt;br /&gt;
&lt;br /&gt;
{{Prices|1750|2950|3950|300987440|300987441|300987442}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Network filters]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/DICOM_Reader</id>
		<title>DICOM Reader</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/DICOM_Reader"/>
				<updated>2026-07-28T08:50:14Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--RM_ID:70--&amp;gt;&lt;br /&gt;
&amp;lt;!--H1:DICOM Reader--&amp;gt;&lt;br /&gt;
&amp;lt;!--TITLE:DICOM Reader DirectShow filter--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:DirectShow reader filter for DICOM files.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:DICOM Reader DirectShow Parsing Medicine--&amp;gt;&lt;br /&gt;
{{This|products/splitters/dicom_reader.html}}&lt;br /&gt;
&lt;br /&gt;
DirectShow reader filter for DICOM files.&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
DICOM (Digital Imaging and Communication in Medicine) is a file format standard commonly used in medical imaging. Our DICOM Reader DirectShow Filter is designed for playback of DICOM files with MPEG-2 media. It parses data in a DICOM file, extracts media streams and transmits them to a splitter (demultiplexer). The filter supports IAsyncReader.&lt;br /&gt;
&lt;br /&gt;
For playback of MPEG-2 media an [[MPEG-2 Video Decoder|MPEG-2 Video Decoder]] is required.&lt;br /&gt;
&lt;br /&gt;
==Features==&lt;br /&gt;
&lt;br /&gt;
* Supports DICOM MPEG PS streams with video and audio data.&lt;br /&gt;
{{.idl}}&lt;br /&gt;
&lt;br /&gt;
==Supported Standards==&lt;br /&gt;
&lt;br /&gt;
* National Electrical Manufacturers Association, 2007: Digital Imaging and Communication in Medicine (DICOM)&lt;br /&gt;
&lt;br /&gt;
==Related Products==&lt;br /&gt;
&lt;br /&gt;
* [[MPEG-2 Video Decoder]]&lt;br /&gt;
* [[MP4 &amp;amp; QuickTime File Splitter]]&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
&lt;br /&gt;
* [[DICOM Reader: Technical Specs]]&lt;br /&gt;
* [[DICOM Reader: Release Notes]]&lt;br /&gt;
&lt;br /&gt;
===Action Items===&lt;br /&gt;
&lt;br /&gt;
* {{DICOM Reader DirectShow Filter: Download}}&lt;br /&gt;
* {{Contact Support}}&lt;br /&gt;
* {{Place Order!}}&lt;br /&gt;
&lt;br /&gt;
{{Prices|950|1650|2400|300606784|300606785|300606786}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Splitters]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Pipe_for_ffmpeg</id>
		<title>Pipe for ffmpeg</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Pipe_for_ffmpeg"/>
				<updated>2026-07-28T08:41:37Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;!--RM_ID:153--&amp;gt;&lt;br /&gt;
&amp;lt;!--TITLE:Pipe for ffmpeg DirectShow filter--&amp;gt;&lt;br /&gt;
&amp;lt;!--DESCRIPTION:DirectShow filter-pipe for encoding video and audio streams and writing them to files using ffmpeg.exe.--&amp;gt;&lt;br /&gt;
&amp;lt;!--KEYWORDS:Pipe ffmpeg encoder muxer DirectShow filter--&amp;gt;&lt;br /&gt;
{{This|products/special_filters/pipe_for_ffmpeg.html}}&lt;br /&gt;
&lt;br /&gt;
{{Pipe for ffmpeg: Description}}&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
Pipe for ffmpeg uses the ffmpeg.exe external module to encode video and audio streams and write them to files. The encoding and file types depend on the ffmpeg.exe used. You can download it from https://www.ffmpeg.org/download.html.&lt;br /&gt;
&lt;br /&gt;
==Features==&lt;br /&gt;
&lt;br /&gt;
The path to the external ffmpeg module to be used must be specified.&lt;br /&gt;
&lt;br /&gt;
The following encoders and file types were tested:&lt;br /&gt;
* video: mpeg2video, mpeg4, libxvid, libx264, libx265&lt;br /&gt;
* audio: copy, aac, ac3, mp2, libmp3lame, libopus, flac&lt;br /&gt;
* files: mp4, mov, avi, mkv, mpg&lt;br /&gt;
Additional parameters (bitrate and other encoding characteristics) can also be specified, please see [[Pipe for ffmpeg: Settings]]&lt;br /&gt;
&lt;br /&gt;
The tests used &amp;quot;FFmpeg 64-bit static Windows build from www.gyan.dev&amp;quot; (Version: 2024-10-24-git-153a6dc8fa-full_build-www.gyan.dev).&lt;br /&gt;
&lt;br /&gt;
{{.idl}}&lt;br /&gt;
&lt;br /&gt;
==Supported Formats==&lt;br /&gt;
&lt;br /&gt;
* Input video streams are RGB or YUV, 8 or 10 bits, 4:2:0, 4:2:2 or 4:4:4 color spaces:&amp;lt;br&amp;gt;- MEDIATYPE_Video, FORMAT_VideoInfo or FORMAT_VideoInfo2&amp;lt;br&amp;gt;- 8 bit color spaces: NV12, YV12, I420, YUY2, UYVY, YVYU, Y422, ARGB32, RGB32, RGB24&amp;lt;br&amp;gt;- 10 bit color spaces: v210, r210&lt;br /&gt;
&lt;br /&gt;
* Input audio streams are PCM or IEEE_FLOAT:&amp;lt;br&amp;gt;- MEDIASUBTYPE_PCM (8 -:- 32 bits, up to 32 channels)&amp;lt;br&amp;gt;- MEDIASUBTYPE_IEEE_FLOAT (32 bits, up to 32 channels)&lt;br /&gt;
&lt;br /&gt;
==Possible filter extensions==&lt;br /&gt;
&lt;br /&gt;
* Adding output pins to further pass input streams (with removed timestamps) to renderers or other filters for monitoring.&lt;br /&gt;
* Adding the ability to start/stop capturing at any time while the graph is running. This can be used to capture specific fragments of input streams into one or more files.&lt;br /&gt;
If you are interested in these extensions or have any other additional requests, please contact us at [mailto:support@avobjects.com support@avobjects.com]&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
&lt;br /&gt;
* [[Pipe for ffmpeg: Settings]]&lt;br /&gt;
* [[Pipe for ffmpeg: Release Notes]]&lt;br /&gt;
&lt;br /&gt;
==You Might Also Need==&lt;br /&gt;
&lt;br /&gt;
The PipeFFTest samples use the following filters:&lt;br /&gt;
* {{LinkDescription|Video Generator}}&lt;br /&gt;
* {{LinkDescription|Wave Generator}}&lt;br /&gt;
&lt;br /&gt;
===Action Items===&lt;br /&gt;
&lt;br /&gt;
* {{Pipe for ffmpeg: Download}}&lt;br /&gt;
* {{Contact Support}}&lt;br /&gt;
* {{Place Order!}}&lt;br /&gt;
&lt;br /&gt;
{{Prices|950|1650|2400|000|000|000}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Special Filters]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	<entry>
		<id>http://wiki.avobjects.com/Download</id>
		<title>Download</title>
		<link rel="alternate" type="text/html" href="http://wiki.avobjects.com/Download"/>
				<updated>2026-07-28T08:38:09Z</updated>
		
		<summary type="html">&lt;p&gt;Dkn: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&amp;lt;!--TABLE.Download--&amp;gt;&lt;br /&gt;
==DirectShow Filters==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--TABLE.Download--&amp;gt;&lt;br /&gt;
{| border = &amp;quot;1&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|Product&lt;br /&gt;
|Description&lt;br /&gt;
|Latest Version&lt;br /&gt;
|  &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[AAC Encoder]]&lt;br /&gt;
|{{AAC Encoder: Description}}&lt;br /&gt;
|[[AAC Encoder: Release Notes|1.2.2.0 [ Feb 03, 2023 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/108 download &amp;lt;span hidden&amp;gt;AAC Encoder&amp;lt;/span&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Audio Level]]&lt;br /&gt;
|{{Audio Level: Description}}&lt;br /&gt;
|[[Audio Level: Release Notes|2.5.0.0 [ Apr 06, 2021 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/32 download &amp;lt;span hidden&amp;gt;Audio Level]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Audio Mixer]]&lt;br /&gt;
|{{Audio Mixer: Description}}&lt;br /&gt;
|[[Audio Mixer DirectShow Filter: Release Notes|3.2.1.0 [ Jan 25, 2025 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/20 download &amp;lt;span hidden&amp;gt;Audio Mixer]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Audio/Video Synchronizer]]&lt;br /&gt;
|{{Audio/Video Synchronizer: Description}}&lt;br /&gt;
|[[Audio/Video Synchronizer DirectShow Filter: Release Notes|2.5.0.0 [ Feb 23 2016 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/53 download &amp;lt;span hidden&amp;gt;Audio/Video Synchronizer]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Deinterlacer]]&lt;br /&gt;
|{{Deinterlacer: Description}}&lt;br /&gt;
|[[Deinterlacer: Release Notes|2.0.0.0 [ Feb 26, 2020 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/145 download &amp;lt;span hidden&amp;gt;Deinterlacer]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Delayer]]&lt;br /&gt;
|{{Delayer: Description}}&lt;br /&gt;
|[[Delayer: Release Notes|1.1.2.0 [ Oct 05, 2024 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/152 download &amp;lt;span hidden&amp;gt;Delayer]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[DICOM Reader]]&lt;br /&gt;
|{{DICOM Reader: Description}}&lt;br /&gt;
|[[DICOM Reader: Release Notes|2.0.0.0 [ Jul 10, 2026 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/70 download &amp;lt;span hidden&amp;gt;DICOM Reader]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[DVCPRO HD Decoder|DV Decoder]]&lt;br /&gt;
|{{DVCPRO HD Decoder: Description}}&lt;br /&gt;
|[[DV Decoder: Release Notes|3.0.1.0 [ Apr 01, 2024 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/7 download &amp;lt;span hidden&amp;gt;DVCPRO HD Decoder]&lt;br /&gt;
|-&lt;br /&gt;
|[[DV Splitter|DV Splitter]]&lt;br /&gt;
|{{DV Splitter: Description}}&lt;br /&gt;
|[[DV Splitter: Release Notes|1.3.2.0 [ Jun 21, 2023 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/11 download &amp;lt;span hidden&amp;gt;DV Splitter]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[DVCPRO HD Encoder|DV Encoder]]&lt;br /&gt;
|{{DVCPRO HD Encoder: Description}}&lt;br /&gt;
|[[DV Encoder: Release Notes|2.1.2.0 [ Nov 14, 2022 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/33 download &amp;lt;span hidden&amp;gt;DVCPRO HD Encoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[GXF/LXF Reader]]&lt;br /&gt;
|{{GXF/LXF Reader: Description}}&lt;br /&gt;
|[[GXF/LXF Reader: Release Notes|1.2.2.2 [ May 19, 2019 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/123 download &amp;lt;span hidden&amp;gt;GXF/LXF Reader]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[H.264/AVC Decoder]]&lt;br /&gt;
|{{H.264/AVC Decoder: Description}}&lt;br /&gt;
|[[H.264/AVC Video Decoder: Release Notes|2.7.7.0 [ Dec 29, 2023 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/43 download &amp;lt;span hidden&amp;gt;H.264/AVC Decoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[H.264/AVC Encoder]]&lt;br /&gt;
|{{H.264/AVC Encoder: Description}}&lt;br /&gt;
|[[H.264/AVC Video Encoder: Release Notes|2.7.9.1 [ Sep 03, 2020 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/73 download &amp;lt;span hidden&amp;gt;H.264/AVC Encoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[M-JPEG Video Decoder|M-JPEG Decoder]]&lt;br /&gt;
|{{M-JPEG Video Decoder: Description}}&lt;br /&gt;
|[[M-JPEG Video Decoder: Release Notes|2.5.2.0 [ Oct 18, 2016 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/56 download &amp;lt;span hidden&amp;gt;M-JPEG Decoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[M-JPEG Video Encoder|M-JPEG Encoder]]&lt;br /&gt;
|{{M-JPEG Video Encoder: Description}}&lt;br /&gt;
|[[M-JPEG Video Encoder: Release Notes|2.5.3.0 [ Jul 13, 2018 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/57 download &amp;lt;span hidden&amp;gt;M-JPEG Encoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Audio Decoder|MP3 &amp;amp; AAC Audio Decoder]]&lt;br /&gt;
|{{Audio Decoder: Description}}&lt;br /&gt;
|[[Audio Decoder DirectShow Filter: Release Notes|1.6.0.0 [ Mar 16, 2025 &amp;amp;#x5d;]]  &lt;br /&gt;
|[http://www.avobjects.com/downloads/38 download &amp;lt;span hidden&amp;gt;Audio Decoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[MP4 &amp;amp; QuickTime File Splitter|MP4 &amp;amp; QuickTime Splitter]]&lt;br /&gt;
|{{MP4 &amp;amp; QuickTime Splitter: Description}}&lt;br /&gt;
|[[MP4 &amp;amp; QuickTime Splitter: Release Notes|2.6.2.0 [ Apr 24, 2025 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/82 download &amp;lt;span hidden&amp;gt;MP4 &amp;amp; QuickTime Splitter]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[MP4 &amp;amp; QuickTime Writer]]&lt;br /&gt;
|{{MP4 &amp;amp; QuickTime Writer: Description}}&lt;br /&gt;
|[[MP4 &amp;amp; QuickTime Writer: Release Notes|1.3.1.0 [ May 17, 2022 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/127 download &amp;lt;span hidden&amp;gt;MP4 &amp;amp; QuickTime Writer]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[MPEG-2 Video Decoder|MPEG-2 Decoder]]&lt;br /&gt;
|{{MPEG-2 Video Decoder: Description}}&lt;br /&gt;
|[[MPEG-2 Video Decoder DirectShow Filter: Release Notes|2.7.0.0 [ Mar 19, 2020 &amp;amp;#x5d;]]  &lt;br /&gt;
|[http://www.avobjects.com/downloads/36 download &amp;lt;span hidden&amp;gt;MPEG-2 Decoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[MPEG-4 Decoder]]&lt;br /&gt;
|{{MPEG-4 Decoder: Description}}&lt;br /&gt;
|[[MPEG-4 Decoder: Release Notes|2.7.0.0 [ Jan 29, 2025 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/42 download &amp;lt;span hidden&amp;gt;MPEG-4 Decoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[MXF Reader]]&lt;br /&gt;
|{{MXF Reader: Description}}&lt;br /&gt;
|[[MXF Reader: Release Notes|1.11.6.3 [ Dec 15, 2021 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/78 download &amp;lt;span hidden&amp;gt;MXF Reader]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[MXF Writer]]&lt;br /&gt;
|{{MXF Writer: Description}}&lt;br /&gt;
|[[MXF Writer: Release Notes|2.0.9.0 [ Mar 12, 2024 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/105 download &amp;lt;span hidden&amp;gt;MXF Writer]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Pipe for ffmpeg]]&lt;br /&gt;
|{{Pipe for ffmpeg: Description}}&lt;br /&gt;
|[[Pipe for ffmpeg: Release Notes|1.0.3.0 [ Dec 23, 2025 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/153 download &amp;lt;span hidden&amp;gt;Pipe for ffmpeg]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|QT based Decoder&lt;br /&gt;
|{{QT based Decoder: Description}}&lt;br /&gt;
|[[QT based Decoder: Release Notes|1.0.4.2 [ Nov 03, 2017 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/135 download &amp;lt;span hidden&amp;gt;QT based Decoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[QuickSync Decoder]]&lt;br /&gt;
|{{QuickSync Decoder: Description}}&lt;br /&gt;
|[[QuickSync Decoder: Release Notes|1.2.0.0 [ Jun 29, 2024 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/136 download &amp;lt;span hidden&amp;gt;QuickSync Decoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[QuickSync Encoder]]&lt;br /&gt;
|{{QuickSync Encoder: Description}}&lt;br /&gt;
|[[QuickSync Encoder: Release Notes|1.3.1.0 [ Now 28, 2025 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/150 download &amp;lt;span hidden&amp;gt;QuickSync Encoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Resizer Filter]]&lt;br /&gt;
|{{Resizer Filter: Description}}&lt;br /&gt;
|[[Resizer Filter: Release Notes|2.0.1.0 [ Jul 28, 2026 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/139 download &amp;lt;span hidden&amp;gt;Resizer Filter]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[RTMP Server]]&lt;br /&gt;
|{{RTMP Server: Description}}&lt;br /&gt;
|[[RTMP Server: Release Notes|1.0.0.1 [ Jan 22, 2018 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/142 download &amp;lt;span hidden&amp;gt;RTMP Server]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|VANC Decoder&lt;br /&gt;
|{{VANC Decoder: Description}}&lt;br /&gt;
|[[VANC Decoder: Release Notes|1.0.7.0 [ Dec 09, 2015 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/125 download &amp;lt;span hidden&amp;gt;VANC Decoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|Video Converter&lt;br /&gt;
|{{Video Converter: Description}}&lt;br /&gt;
|[[Video Converter: Release Notes|1.0.2.0 [ Sep 11, 2019 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/148 download &amp;lt;span hidden&amp;gt;Video Converter]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|Video Frame Capture&lt;br /&gt;
|{{Video Frame Capture: Description}}&lt;br /&gt;
|[[Video Frame Capture: Release Notes|1.0.2.0 [ Dec 01, 2015 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/124 download &amp;lt;span hidden&amp;gt;Video Frame Capture]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Video Mixer]]&lt;br /&gt;
|{{Video Mixer: Description}}&lt;br /&gt;
|[[Video Mixer: Release Notes|1.9.9.29 [ Apr 19, 2024 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/147 download &amp;lt;span hidden&amp;gt;Video Mixer]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|Video Rotator&lt;br /&gt;
|{{Video Rotator: Description}}&lt;br /&gt;
|[[Video Rotator: Release Notes|1.0.2.0 [ Feb 10, 2016 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/134 download &amp;lt;span hidden&amp;gt;Video Rotator]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[WebRTC/RTP Server]]&lt;br /&gt;
|{{WebRTC/RTP Server: Description}}&lt;br /&gt;
|[[WebRTC/RTP Server: Release Notes|2.5.0.0 [ May 06, 2026 &amp;amp;#x5d;]] &lt;br /&gt;
|[http://www.avobjects.com/downloads/143 download &amp;lt;span hidden&amp;gt;WRtp Server&amp;lt;/span&amp;gt;]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Media Objects==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--TABLE.Download--&amp;gt;&lt;br /&gt;
{| border = &amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Product&lt;br /&gt;
|Description&lt;br /&gt;
|Latest Version&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[MPEG-4 Cutter]]&lt;br /&gt;
|{{MPEG-4 Cutter: Description}}&lt;br /&gt;
|[[MPEG-4 Cutter: Release Notes|1.1.0.0 [ Jun 12, 2020 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://rm.avobjects.com/downloads/141 download &amp;lt;span hidden&amp;gt;MPEG-4 Cutter]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Freeware Filters==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--TABLE.Download--&amp;gt;&lt;br /&gt;
{| border = &amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Product&lt;br /&gt;
|Description&lt;br /&gt;
|Latest Version&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|A/V Synchro Checker&lt;br /&gt;
|{{A/V Synchro Checker: Description}}&lt;br /&gt;
|[[A/V Synchro Checker: Release Notes|1.0.1.0 [ Dec 16, 2015 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/132 download &amp;lt;span hidden&amp;gt;AV Synchro Checker]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Log Object]]&lt;br /&gt;
|{{Log Object: Description}}&lt;br /&gt;
|[[Log Object: Release Notes|2.1.3.0 [ Mar 24, 2025 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/133 download &amp;lt;span hidden&amp;gt;Log Object]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Opus Encoder]]&lt;br /&gt;
|{{Opus Encoder: Description}}&lt;br /&gt;
|[[Opus Encoder: Release Notes|1.1.2.0 [ Feb 28, 2025 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/144 download &amp;lt;span hidden&amp;gt;Opus Encoder]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Spy Filter]]&lt;br /&gt;
|{{Spy Filter: Description}}&lt;br /&gt;
|[[Spy Filter: Release Notes|1.3.4.0 [ Jun 23, 2025 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/130 download &amp;lt;span hidden&amp;gt;Spy filter]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|Timecode Renderer&lt;br /&gt;
|{{Timecode Renderer: Description}}&lt;br /&gt;
|[[Timecode Renderer: Release Notes|1.0.0.1 [ Jan 25, 2017 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/138 download &amp;lt;span hidden&amp;gt;Timecode Renderer]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Video Generator]]&lt;br /&gt;
|{{Video Generator: Description}}&lt;br /&gt;
|[[Video Generator: Release Notes|2.5.3.0 [ Nov 24, 2025 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/121 download &amp;lt;span hidden&amp;gt;Video Generator]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Video Transformer]]&lt;br /&gt;
|{{Video Transformer: Description}}&lt;br /&gt;
|[[Video Transformer: Release Notes|2.2.1.0 [ Aug 16, 2025 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/120 download &amp;lt;span hidden&amp;gt;Video Transformer]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|[[Wave Generator]]&lt;br /&gt;
|{{Wave Generator: Description}}&lt;br /&gt;
|[[Wave Generator: Release Notes|1.1.2.0 [ Apr 07, 2021 &amp;amp;#x5d;]]&lt;br /&gt;
|[http://www.avobjects.com/downloads/151 download &amp;lt;span hidden&amp;gt;Wave Generator]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Dkn</name></author>	</entry>

	</feed>