After reading practically every article on the subject of getting the Ratchet PHP implementation of Websockets to work with SSL, I finally got it working with the help of many tips, although mainly the info here https://github.com/ratchetphp/Ratchet/issues/489 which basically modifies the way you create the IoServer to use React's Secure Server. My implementation at the server end in PHP like so:
$loop = \React\EventLoop\Factory::create();
$secure_websockets = new \React\Socket\Server('0.0.0.0:8080', $loop);
$secure_websockets = new \React\Socket\SecureServer($secure_websockets, $loop, [
'local_cert' => '/path/to/letsencyrpt/cert.crt',
'local_pk' => '/path/to/letsencyrpt/key.key',
'verify_peer' => false
]);
$app = new \Ratchet\Http\HttpServer(
new \Ratchet\WebSocket\WsServer(
new Chat()
)
);
$server = new \Ratchet\Server\IoServer($app, $secure_websockets, $loop);
$server->run();
And on the client side the Javascript:
function startWebsocket() {
var conn = new WebSocket('wss://domain.com:port');
conn.onopen = function(e) {
console.log("Connection established!");
};
}
startWebsocket();
And that works just fine.
BUT... I'm using Let's Encrypt certificates on the server and they have a rather short lifetime. That's fine on https as the host (Siteground) automatically renews the SSL before expiry, but if I'm putting a path to a specific Cert/Key pair (as above), they will expire.
So, are my options:
A: Put a repeating note in my calendar to remind me to update the Cert/Key paths every 3 months and live with it, or.. B: Is there a way to discover the current Cert/Key pair and drop that in as a variable?
Some things to bear in mind:
- I'm on Siteground with a Cloud Server, but not with root access (I stupidly signed up for 'Geeky Features' years ago before my techy knowledge improved enough for me to need root).
- Whilst I don't have root, it is effectively a dedicated server, so I can ask Siteground's support guys to change things for me - but I'd really need to be very specific with any requests. Trying things out is probably not an option here.
- I explored the other method of getting wss: working with Ratchet, namely Proxying the https request over to the ws port. Didn't get very far with that since the version of Apache installed doesn't seem to be recent enough to support the tunnel and although there are references to NGINX running in parallel to Apache on Siteground, I just kept getting error any time I tried to use it to proxy. Didn't help that without root access I'm pretty limited in what I can do.