# Enabling HTTPS Connections
Source: https://docs.chain.link/chainlink-nodes/resources/enabling-https-connections

> For the complete documentation index, see [llms.txt](/llms.txt).

This guide will walk you through how to generate your own self-signed certificates for use by the Chainlink node. You can also substitute self-signed certificates with certificates of your own, like those created by [Let's Encrypt](https://letsencrypt.org/).

> **TIP: TLS**
>
> You will need [OpenSSL](https://www.openssl.org) in order to generate your own self-signed certificates.

Create a directory `tls/` within your local Chainlink directory:

### Sepolia

```text Sepolia
mkdir ~/.chainlink-sepolia/tls
```

### Mainnet

```text Mainnet
mkdir ~/.chainlink/tls
```

Run this command to create a `server.crt` and `server.key` file in the previously created directory:

### Sepolia

```shell Sepolia
openssl req -x509 -out  ~/.chainlink-sepolia/tls/server.crt  -keyout ~/.chainlink-sepolia/tls/server.key \
  -newkey rsa:2048 -nodes -sha256 -days 365 \
  -subj '/CN=localhost' -extensions EXT -config <( \
   printf "[dn]\nCN=localhost\n[req]\ndistinguished_name = dn\n[EXT]\nsubjectAltName=DNS:localhost\nkeyUsage=digitalSignature\nextendedKeyUsage=serverAuth")
```

### Mainnet

```shell Mainnet
openssl req -x509 -out  ~/.chainlink/tls/server.crt  -keyout ~/.chainlink/tls/server.key \
  -newkey rsa:2048 -nodes -sha256 -days 365 \
  -subj '/CN=localhost' -extensions EXT -config <( \
   printf "[dn]\nCN=localhost\n[req]\ndistinguished_name = dn\n[EXT]\nsubjectAltName=DNS:localhost\nkeyUsage=digitalSignature\nextendedKeyUsage=serverAuth")
```

Next, add the certificate and key paths to the `[WebServer.TLS]` section of your `config.toml` file. Set `SecureCookies` to `true` and `HTTPSPort` to the HTTPS port:

```toml config.toml
[WebServer]
SecureCookies = true

[WebServer.TLS]
CertPath = '/chainlink/tls/server.crt'
KeyPath = '/chainlink/tls/server.key'
HTTPSPort = 6689
```

Finally, update your run command to forward port 6689 to the container instead of 6688:

### Sepolia

```shell Sepolia
cd ~/.chainlink-sepolia && docker run -p 6689:6689 -v ~/.chainlink-sepolia:/chainlink -it smartcontract/chainlink:2.66.0 node -config /chainlink/config.toml -secrets /chainlink/secrets.toml start
```

### Mainnet

```shell Mainnet
cd ~/.chainlink && docker run -p 6689:6689 -v ~/.chainlink:/chainlink -it smartcontract/chainlink:2.66.0 node -config /chainlink/config.toml -secrets /chainlink/secrets.toml start
```

Now when running the node, you can access it by navigating to [https://localhost:6689](https://localhost:6689) if running on the same machine or with a ssh tunnel.