SSL Certificate for Localhost
Using HTTPS has become mandatory for all sites and web applications today. However, some difficulties come up when running proper tests during development. Let's Encrypt and other Certificate Authorities (CAs) stopped issuing certificates for localhost as of November 1, 2015. Because of this, there are two solutions for HTTPS testing on localhost:
Solution 1: Self-Signed SSL
Self-signed certificates can be created with tools like openssl. Below is the simplest way to generate a private key and a self-signed certificate for localhost:
- Generate a Private Key:
openssl genrsa -out localhost.key 2048 - Generate a Self-Signed Certificate:
openssl req -new -x509 -key localhost.key -out localhost.crt -days 365
Although these certificates are marked as untrusted by browsers, they can be used locally during development.
Solution 2: mkcert
Another method is to use mkcert. Mkcert is a simple helper tool for generating locally-trusted certificates, working with its own certificate authority. It works on all operating systems and requires no configuration.
- Installation: mkcert is available on Windows, macOS and Linux.
- Usage: to generate a certificate trusted on your local machine, use the following commands:
mkcert -installmkcert localhost 127.0.0.1 ::1
Mkcert is recommended as the safest and simplest solution for testing secure HTTPS connections on localhost.
On Linux
First, you need to install certutil.
sudo apt install libnss3-tools\n-or-\nsudo yum install nss-tools\n-or-\nsudo pacman -S nss
or
brew install mkcert
then
brew install mkcert
or build from source:
github.com/FiloSottile/mkcert get $( go \nenv GOPATH)/bin/mkcert
On macOS
You can follow these commands.
brew install mkcert \nbrew install nss # if you use Firefox
On Windows
You can download the prebuilt binaries or use one of the Chocolatey or Scoop package managers.
choco install mkcert\n -or- \nscoop install mkcert
Can't find the answer you need?
Contact Us