# Howto encrypt key file

**URL:** <https://discourse.haproxy.org/t/howto-encrypt-key-file/8388>\
**Category:** Help!\
**Created:** [February 10, 2023, 10:59am UTC](https://discourse.haproxy.org/t/howto-encrypt-key-file/8388 "2023-02-10T10:59:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![zahid](https://avatars.discourse-cdn.com/v4/letter/z/e79b87/32.png) [@zahid](https://discourse.haproxy.org/u/zahid)\
**Post date:** [February 10, 2023, 10:59am UTC](https://discourse.haproxy.org/t/howto-encrypt-key-file/8388/1 "2023-02-10T10:59:42Z")

</div>

We have setup haproxy and its working fine. We enable ssl as well. We actually have a .pem file with a combination of .crt and .key. Now we want to secure the key so that no one can view it. Please advice what we need to do ?

---

<div class="post-metadata">

**Author:** ![stormrover](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.haproxy.org/stormrover/32/1847_2.png) [@stormrover](https://discourse.haproxy.org/u/stormrover)\
**Post date:** [February 10, 2023, 5:56pm UTC](https://discourse.haproxy.org/t/howto-encrypt-key-file/8388/2 "2023-02-10T17:56:20Z")

</div>

I don’t think what you’re asking for is currently possible. I’ve seen something like this in Nginx’s documentation, but even they say:

> For the large majority of organizations, it is sufficient to restrict access to the environments running NGINX so that unauthorized users cannot gain `root` access and cannot look at NGINX configuration.

(Source: [Secure Distribution of SSL Private Keys with NGINX - NGINX](https://www.nginx.com/blog/secure-distribution-ssl-private-keys-nginx/))

If other users can gain root, there’s no point in taking any further action, as users would still have the ability to see the key. My certificates are automated, and they are set with:  
`chown haproxy /path/to/the/cert` ← Sets HAProxy as the owner  
`chmod 400 /path/to/the/cert` ← Sets the permissions where only the owner can read the file.  
Of course, root always has permission to everything. With these settings, no other user can read the file except for the owner (haproxy) and root.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [February 11, 2023, 4:57pm UTC](https://discourse.haproxy.org/t/howto-encrypt-key-file/8388/3 "2023-02-11T16:57:05Z")

</div>

The haproxy user in most cases does not need access to the certificates, because haproxy usually starts as root, bind all the ports and reads all the files it needs to read as root, and only afterwards drops privileges to whatever user is specified.

So you could `chown root:root` and `chmod 000` it if you want.
