SECUREXSECURITY ENGINEERINGNVR 文档

TLS / HTTPS

Securex NVR 的认证与 TLS 应按“浏览器/APP → 反向代理/入口 → Securex 服务”的链路设计。公网访问时不要直接暴露未加密管理端口;优先使用 HTTPS、强密码、受控反向代理或 VPN。

推荐架构

# Example reverse-proxy concept (actual syntax depends on your proxy)
Client -> HTTPS reverse proxy -> Securex NVR internal HTTP service

认证

  • 为管理员与普通访问者分配独立账号/权限。
  • 避免共享默认密码;启用强密码和必要的二次认证能力。
  • 反向代理做认证时,要确认 Securex 自身认证与代理认证不会互相造成循环/重复登录。

TLS / HTTPS

  • 证书域名必须与访问域名匹配。
  • 反向代理到内网 Securex 时可使用受控的 HTTP 内部链路,但外部客户端应为 HTTPS。
  • WebSocket/WebRTC/API 经过代理时要同时转发所需头和升级连接。

常见错误

现象方向
登录循环代理认证与应用认证冲突、Cookie domain/path、X-Forwarded-* 头。
502上游端口、容器网络或服务未启动。
证书警告域名不匹配、链不完整、过期。
APP 能开网页但 API 登录失败base path、反向代理重写或认证 API 没有透传。

安全建议

不要把 API Key、摄像头 RTSP 密码或管理员密码写入公开文档。对公网部署,限制管理接口来源并保持 Securex、反向代理与操作系统更新。

TLS / HTTPS

Design authentication and TLS as a complete path: client → reverse proxy/edge → Securex service. Do not expose an unencrypted management port directly to the Internet; prefer HTTPS, strong credentials, a controlled proxy, or VPN.

Recommended architecture

# Example reverse-proxy concept (actual syntax depends on your proxy)
Client -> HTTPS reverse proxy -> Securex NVR internal HTTP service

Authentication

  • Use separate accounts/permissions for administrators and viewers.
  • Replace default/shared passwords.
  • When the proxy authenticates users too, make sure proxy auth and Securex auth do not create loops or double-login failures.

TLS / HTTPS

  • Certificate names must match the hostname.
  • An internal HTTP hop may be acceptable on a controlled network, while external clients should use HTTPS.
  • Proxy WebSocket/WebRTC/API upgrade headers correctly.

Common failures

SymptomDirection
Login loopConflicting auth, cookie domain/path, X-Forwarded headers.
502Wrong upstream port/network/service state.
Certificate warningHostname mismatch, incomplete chain, or expiry.
Web page works but app API login failsBase path, rewrite, or auth API not being proxied correctly.

Security

Do not publish API keys, RTSP passwords, or admin credentials. Restrict management exposure and keep the OS, proxy, and Securex components current.

TLS / HTTPS

Diseñe autenticación y TLS como una ruta completa: cliente → proxy/entrada → Securex. No exponga un puerto de administración sin cifrar directamente a Internet.

Arquitectura

# Example reverse-proxy concept (actual syntax depends on your proxy)
Client -> HTTPS reverse proxy -> Securex NVR internal HTTP service

Autenticación

  • Separe cuentas/permisos.
  • Cambie contraseñas por defecto.
  • Evite conflictos entre autenticación del proxy y de Securex.

TLS/HTTPS

  • El certificado debe coincidir con el dominio.
  • El cliente externo debe usar HTTPS.
  • Proxy WebSocket/WebRTC/API correctamente.

Errores

SíntomaRevisar
Bucle de loginAuth duplicada, cookies, X-Forwarded.
502Puerto/red/servicio upstream.
Aviso de certificadoDominio/cadena/caducidad.
Web funciona, app API noBase path, rewrite o auth API.

Seguridad

No publique claves ni contraseñas y mantenga el sistema actualizado.

输入关键词开始搜索