# Certificate questions

> Why Fregata Mobile asks whether to trust your server's certificate, when it trusts one by itself, what "This server's certificate has changed" means, and how to forget a trusted certificate.

Frigate secures its web interface with a certificate it makes for itself. iOS can't vouch for one
of those, so Fregata Mobile decides for itself, and remembers: once a certificate is trusted, the
app expects exactly that one from then on. If anything else answers at your server's address, it
stops and asks rather than sending your password to it.

## When it asks, and when it doesn't

| The certificate | What the app does |
|---|---|
| Frigate's own, on an address on your home network, such as `192.168.1.10` | Trusts it the first time, by itself, and remembers it. |
| Frigate's own, on any other address | Asks: **Trust this server's certificate?** |
| One iOS already trusts, such as Let's Encrypt on a reverse proxy | Trusts it, with no question, and forgets any certificate it remembered before. |
| A different one from the one it remembers | Asks: **This server's certificate has changed**. |

_Picture: The question Trust this server's certificate?, explaining that iOS cannot verify it on its own, which is normal for Frigate, with the certificate's SHA-256 fingerprint, a note that it doesn't name this server, and the buttons Trust it and Not now._

## Trust this server's certificate?

The question shows the certificate's **SHA-256 fingerprint**. To be certain it's your server, compare
it with the fingerprint your server shows, for example by running
`openssl x509 -noout -fingerprint -sha256 -in cert.pem` on the server, then tap **Trust it**.

The question may add two notes, neither of which is a problem on its own with Frigate:

- **It does not name this server.** Frigate's default certificate names nothing at all.
- **It is outside its validity dates.** Frigate makes its certificate once, valid for a year, and
  never renews it, so a server older than a year always shows this.

**Not now** leaves the server unconnected; the question comes back next time.

## This server's certificate has changed

The app had trusted a certificate for this server, and now a different one answers. Two things
cause that:

- **Your server made a new one.** Frigate makes a new certificate when it's rebuilt or reinstalled,
  or can't find its old one. If you've just done that, this is expected: tap **Trust it**.
- **Something is intercepting the connection**, such as a network you don't control. If you haven't
  changed anything on the server, tap **Not now** and find out why before trusting it.

## Forget a trusted certificate

**Settings › Diagnostics** shows the certificate in use for the server, and **Forget all trusted
certificates** clears every one the app remembers. The next connection to each server trusts
whatever it presents, by the rules above. Each device decides for itself which certificates to
trust: this isn't synced.
