Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Encrypt data traffic

Encrypt data traffic

Scheduled Pinned Locked Moved Solved Support
tls
9 Posts 2 Posters 1.2k Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L Offline
    L Offline
    lukas
    wrote on last edited by girish
    #1

    Hello community,

    Is there a way / option to encrypt my traffic going to and from Cloudron? I am planning to host some "family" stuff like videos, pictures ... and don't want anyone to be able to "intercept" my traffic and see what data is going to and from the Cloudron server.

    Regards
    Lukas

    1 Reply Last reply
    1
    • girishG Offline
      girishG Offline
      girish
      Staff
      wrote on last edited by
      #2

      @lukas as long as you have certificates for apps, everything is already encrypted via TLS. Nobody can intercept Cloudron traffic. Even if they did, we use perfect forward secrecy ciphers (ECDHE) which prevents replay attacks (if someone 'recorded' your traffic).

      1 Reply Last reply
      1
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #3

        You can actually test your domain/site here - https://www.ssllabs.com/ssltest/analyze.html . You will see a line like below in the report:

        image.png

        1 Reply Last reply
        0
        • girishG girish marked this topic as a question on
        • L Offline
          L Offline
          lukas
          wrote on last edited by
          #4

          So does this mean that if I have SSL active for my applications, the data traffic cannot be intercepted and decrypted, i.e. nobody can read it?

          1 Reply Last reply
          0
          • girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by
            #5

            @lukas yes

            1 Reply Last reply
            1
            • L Offline
              L Offline
              lukas
              wrote on last edited by
              #6

              @girish great! which would be very cool if the application data could be encrypted

              1 Reply Last reply
              0
              • girishG Offline
                girishG Offline
                girish
                Staff
                wrote on last edited by
                #7

                @lukas that is more a server/OS level feature called FDE. See https://forum.cloudron.io/topic/2939/optional-full-disc-encryption . You can always setup FDE on your server and install Cloudron on top of that.

                1 Reply Last reply
                1
                • girishG girish has marked this topic as solved on
                • L Offline
                  L Offline
                  lukas
                  wrote on last edited by
                  #8

                  thank you, so per App "data encryption" is not on the roadmap?

                  1 Reply Last reply
                  0
                  • girishG Offline
                    girishG Offline
                    girish
                    Staff
                    wrote on last edited by
                    #9

                    @lukas you can attach an external disk which has encryption and move the Cloudron App Data (https://docs.cloudron.io/apps/#data-directory) to that volume.

                    It's not possible to enable encryption at the per app level when the underlying disk is not encrypted. I think this requires creating loopback mounts (which should not be used for production) and setting up encryption. All this goes against best practices.

                    1 Reply Last reply
                    1
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Don't have an account? Register

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • Bookmarks
                    • Search