> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.itential.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server.

# Configure HTTPS

> Configure HTTPS/TLS settings for Itential Gateway using SSL certificates and Unix socket binds.

Itential Gateway uses Gunicorn to serve Web Server Gateway Interface (WSGI) web requests to the backend python application.

* For production instances of Gateway you may want to use Nginx as a front-end proxy to Gunicorn. For more information on Nginx deployments with Gunicorn, refer to the [Gunicorn deployment](https://gunicorn.org/deploy/) documentation.
* If using a front-end proxy, enable HTTPS/TLS settings and use a [Unix-style socket bind](#configure-iag-to-bind-to-a-unix-socket) for Gateway.

> **Info**
>
> Refer to the [System requirements](./system-requirements) for information regarding the **Software Repository and Registry Credentials** that can be used with the various Gateway installation methods.

## Basic HTTPS configuration options

To configure the SSL certificate and key files in the **properties.yml** file:

```yaml
################
# SSL Settings #
################

# To start the server using SSL/TLS please fill out the following properties.
#server_certfile: "/app/cert.pem"

# Note: gunicorn does not currently support encrypted key files.
#server_keyfile: "/app/key.pem"

#server_cabundle: "~/cabundle.crt" 

# TLSv1_2
#server_ssl_version: "TLSv1_2"

# You may also set custom SSL Ciphers.
#
# https://docs.gunicorn.org/en/20.x/settings.html#ciphers
#
# server_ssl_ciphers: "ECDHE-ECDSA-AES128-GCM-SHA256:...""
```

To restart the automation-gateway application to serve traffic over HTTPS:

```bash
systemctl restart automation-gateway
```

## Configure Gateway to bind to a UNIX socket

Use a `unix://` style bind string set in a `bind_address` to bind the socket and give it a unique name. Using local sockets is more performant and may be more secure than using TCP proxies when using Nginx or another front-end proxy.

Below is an example of using a Unix-style socket bind.

```yaml
bind_address: "unix:///tmp/gunicorn.sock"
```