Why Do I Need HTTPS?
What breaks without HTTPS, and how to fix it.
Browsers only give a page access to the microphone, webcam, and screen in a secure context: HTTPS, or http://localhost. Over plain HTTP on any other address, those requests are blocked before Sharkord ever sees them.
So without HTTPS:
- Text chat, file sharing, and everything else still work.
- Voice, webcam, and screen sharing do not.
- Traffic between your users and the server is unencrypted, including their passwords.
Testing locally on http://localhost is fine. Anything else needs a certificate. See Voice and Devices for what those blocked features are.
How to Set It Up
Sharkord does not terminate TLS itself. Put a reverse proxy in front of it, point your domain at the server, and let the proxy handle certificates:
- Caddy: the easiest option. Certificates are automatic.
- Nginx: certificates through certbot.
- Apache: certificates through certbot.
- Docker Compose: Sharkord and Caddy together in one file, and the one we recommend. There is a one minute video of it if you prefer.
No domain? Claim a free subdomain.
The reverse proxy handles HTTP and WebSocket traffic on port 4991 only. Voice
and video go directly to port 40000 over UDP and TCP, so that port has to
stay open in your firewall.