TLS / HTTPS
Securex NVR 的认证与 TLS 应按“浏览器/APP → 反向代理/入口 → Securex 服务”的链路设计。公网访问时不要直接暴露未加密管理端口;优先使用 HTTPS、强密码、受控反向代理或 VPN。
推荐架构
# Example reverse-proxy concept (actual syntax depends on your proxy)
Client -> HTTPS reverse proxy -> Securex NVR internal HTTP service认证
- 为管理员与普通访问者分配独立账号/权限。
- 避免共享默认密码;启用强密码和必要的二次认证能力。
- 反向代理做认证时,要确认 Securex 自身认证与代理认证不会互相造成循环/重复登录。
TLS / HTTPS
- 证书域名必须与访问域名匹配。
- 反向代理到内网 Securex 时可使用受控的 HTTP 内部链路,但外部客户端应为 HTTPS。
- WebSocket/WebRTC/API 经过代理时要同时转发所需头和升级连接。
常见错误
| 现象 | 方向 |
|---|---|
| 登录循环 | 代理认证与应用认证冲突、Cookie domain/path、X-Forwarded-* 头。 |
| 502 | 上游端口、容器网络或服务未启动。 |
| 证书警告 | 域名不匹配、链不完整、过期。 |
| APP 能开网页但 API 登录失败 | base path、反向代理重写或认证 API 没有透传。 |
安全建议
不要把 API Key、摄像头 RTSP 密码或管理员密码写入公开文档。对公网部署,限制管理接口来源并保持 Securex、反向代理与操作系统更新。
TLS / HTTPS
Design authentication and TLS as a complete path: client → reverse proxy/edge → Securex service. Do not expose an unencrypted management port directly to the Internet; prefer HTTPS, strong credentials, a controlled proxy, or VPN.
Recommended architecture
# Example reverse-proxy concept (actual syntax depends on your proxy)
Client -> HTTPS reverse proxy -> Securex NVR internal HTTP serviceAuthentication
- Use separate accounts/permissions for administrators and viewers.
- Replace default/shared passwords.
- When the proxy authenticates users too, make sure proxy auth and Securex auth do not create loops or double-login failures.
TLS / HTTPS
- Certificate names must match the hostname.
- An internal HTTP hop may be acceptable on a controlled network, while external clients should use HTTPS.
- Proxy WebSocket/WebRTC/API upgrade headers correctly.
Common failures
| Symptom | Direction |
|---|---|
| Login loop | Conflicting auth, cookie domain/path, X-Forwarded headers. |
| 502 | Wrong upstream port/network/service state. |
| Certificate warning | Hostname mismatch, incomplete chain, or expiry. |
| Web page works but app API login fails | Base path, rewrite, or auth API not being proxied correctly. |
Security
Do not publish API keys, RTSP passwords, or admin credentials. Restrict management exposure and keep the OS, proxy, and Securex components current.
TLS / HTTPS
Diseñe autenticación y TLS como una ruta completa: cliente → proxy/entrada → Securex. No exponga un puerto de administración sin cifrar directamente a Internet.
Arquitectura
# Example reverse-proxy concept (actual syntax depends on your proxy)
Client -> HTTPS reverse proxy -> Securex NVR internal HTTP serviceAutenticación
- Separe cuentas/permisos.
- Cambie contraseñas por defecto.
- Evite conflictos entre autenticación del proxy y de Securex.
TLS/HTTPS
- El certificado debe coincidir con el dominio.
- El cliente externo debe usar HTTPS.
- Proxy WebSocket/WebRTC/API correctamente.
Errores
| Síntoma | Revisar |
|---|---|
| Bucle de login | Auth duplicada, cookies, X-Forwarded. |
| 502 | Puerto/red/servicio upstream. |
| Aviso de certificado | Dominio/cadena/caducidad. |
| Web funciona, app API no | Base path, rewrite o auth API. |
Seguridad
No publique claves ni contraseñas y mantenga el sistema actualizado.
