Local HTTPS with Trusted Certs¶
TL;DR / when to use this: Running apps on https:// inside the LAN is easy with Caddy's tls internal, but the self-signed cert isn't trusted by clients until you import its root CA. This guide covers Caddy (preferred), Nginx Proxy Manager as an alternative, and how to trust the cert on Linux/Windows. For public-facing certs, see SWAG or Cloudflare Tunnel.
Caddy (preferred)¶
Install Caddy, then edit the Caddyfile:
tls internal generates a local CA and per-host certs automatically. Use any free port for the HTTPS listener (2282 here, mapping to Immich's 2283). Restart:
Trusting the cert¶
The connection is encrypted, but clients won't trust the self-signed root until imported.
Linux:
sudo cp ~/.local/share/caddy/pki/authorities/local/root.crt /usr/local/share/ca-certificates/caddy.crt
sudo update-ca-certificates
(From a service install, the path is /var/lib/caddy/.local/share/caddy/pki/authorities/local/root.crt — copy it somewhere portable for other machines.)
Windows: MMC (Win+R → mmc) → Add/Remove Snap-in → Certificates → Computer account → Local computer → Trusted Root Certification Authorities → All Tasks → Import → select root.crt. Verify it appears under Trusted Root Certification Authorities.
Nginx Proxy Manager (alternative)¶
NPM can serve the same trusted cert via Cloudflare — see Hosting local https with trusted cert from Cloudflare with NPM for the walkthrough, and the Caddy variant of the same approach in the companion post. If Cloudflare is already fronting the domain, its Universal SSL + "Full (strict)" is often simpler than a local CA.
.local names (mDNS caveat)¶
A Caddy block like:
only resolves on the machine itself unless mDNS works network-wide. avahi-daemon + avahi-utils (avahi-browse -art, avahi-publish -a immich.local -R <ip>) advertise the name, but in my experience other devices didn't resolve immich.local reliably — don't build a setup that depends on .local names across the LAN. Prefer an IP:port, a real subdomain, or the context-aware DNS approach in Context-Aware DNS.