Skip to content

Certificate questions

Frigate secures its web interface with a certificate it makes for itself. iOS can’t vouch for one of those, so Fregata Mobile decides for itself, and remembers: once a certificate is trusted, the app expects exactly that one from then on. If anything else answers at your server’s address, it stops and asks rather than sending your password to it.

The certificate What the app does
Frigate’s own, on an address on your home network, such as 192.168.1.10 Trusts it the first time, by itself, and remembers it.
Frigate’s own, on any other address Asks: Trust this server’s certificate?
One iOS already trusts, such as Let’s Encrypt on a reverse proxy Trusts it, with no question, and forgets any certificate it remembered before.
A different one from the one it remembers Asks: This server’s certificate has changed.

The question shows the certificate’s SHA-256 fingerprint. To be certain it’s your server, compare it with the fingerprint your server shows, for example by running openssl x509 -noout -fingerprint -sha256 -in cert.pem on the server, then tap Trust it.

The question may add two notes, neither of which is a problem on its own with Frigate:

  • It does not name this server. Frigate’s default certificate names nothing at all.
  • It is outside its validity dates. Frigate makes its certificate once, valid for a year, and never renews it, so a server older than a year always shows this.

Not now leaves the server unconnected; the question comes back next time.

The app had trusted a certificate for this server, and now a different one answers. Two things cause that:

  • Your server made a new one. Frigate makes a new certificate when it’s rebuilt or reinstalled, or can’t find its old one. If you’ve just done that, this is expected: tap Trust it.
  • Something is intercepting the connection, such as a network you don’t control. If you haven’t changed anything on the server, tap Not now and find out why before trusting it.

Settings › Diagnostics shows the certificate in use for the server, and Forget all trusted certificates clears every one the app remembers. The next connection to each server trusts whatever it presents, by the rules above. Each device decides for itself which certificates to trust: this isn’t synced.