# Encryption used by mattermost

**URL:** <https://forum.mattermost.com/t/encryption-used-by-mattermost/6911>\
**Category:** Troubleshooting\
**Created:** [March 24, 2019, 6:28pm UTC](https://forum.mattermost.com/t/encryption-used-by-mattermost/6911 "2019-03-24T18:28:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vibhi](https://avatars.discourse-cdn.com/v4/letter/v/977dab/32.png) [@vibhi](https://forum.mattermost.com/u/vibhi)\
**Post date:** [March 24, 2019, 6:28pm UTC](https://forum.mattermost.com/t/encryption-used-by-mattermost/6911/1 "2019-03-24T18:28:33Z")

</div>

What type of encryption is used by mattermost?  
if there are encryption is it enabled by default?

---

<div class="post-metadata">

**Author:** ![dannymohammad](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/dannymohammad/32/2489_2.png) [@dannymohammad](https://forum.mattermost.com/u/dannymohammad)\
**Post date:** [March 25, 2019, 12:15am UTC](https://forum.mattermost.com/t/encryption-used-by-mattermost/6911/2 "2019-03-25T00:15:36Z")

</div>

Hi there, @vibhi

You can refer to the official documentation - [Encryption Options](https://docs.mattermost.com/administration/encryption.html) for more information on the type of encryptions offered by Mattermost, which is categorized into two types:

- Encryption-in-transit
- Encryption-at-rest

They are not enabled by default as you will have to set them up accordingly:

> You may either set up TLS on the Mattermost Server or install a proxy such as NGINX and set up TLS on the proxy. Refer to our [configuration guide for more details](https://docs.mattermost.com/install/config-tls-mattermost.html).

> Encryption options at the disk level are documented both for [MySQL](https://www.percona.com/blog/2016/04/08/mysql-data-at-rest-encryption/) and [PostgreSQL](https://www.postgresql.org/docs/8.1/static/encryption-options.html).

> For local storage or storage via Minio, encryption-at-rest is available for files stored via hardware and software disk encryption solutions applied to the server.

So, it really depends on the setup of your infrastructure.

---

<div class="post-metadata">

**Author:** ![vibhi](https://avatars.discourse-cdn.com/v4/letter/v/977dab/32.png) [@vibhi](https://forum.mattermost.com/u/vibhi)\
**Post date:** [March 25, 2019, 6:39pm UTC](https://forum.mattermost.com/t/encryption-used-by-mattermost/6911/4 "2019-03-25T18:39:17Z")

</div>

TLS is basically a encryption between user and server that is doen by default or if you use cloudflare?

What is the difference here ?

What type of encryption should i use which will be enough for user? basically making sure there private information remain safe. Sent files and Msg need to be encrypted (e2e) or somewhat near that .

---

<div class="post-metadata">

**Author:** ![dannymohammad](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/dannymohammad/32/2489_2.png) [@dannymohammad](https://forum.mattermost.com/u/dannymohammad)\
**Post date:** [March 26, 2019, 12:39am UTC](https://forum.mattermost.com/t/encryption-used-by-mattermost/6911/5 "2019-03-26T00:39:41Z")

</div>

Hello, @vibhi

The TLS setup is to be configured based on your preference. If you refer to the [Configuring TLS on Mattermost Server](https://docs.mattermost.com/install/config-tls-mattermost.html#configuring-tls-on-mattermost-server). In case of setting up SSL on your server, you will need to make configuration changes on **System Console** \> **General** \> **Configuration**. I came across users utilizing Cloudfare for encryption, so it is another option that you can consider :

- [Cloudflare and websockets with SSL (free Cloudflare accounts block websocket connection)](https://forum.mattermost.com/t/cloudflare-and-websockets-with-ssl-free-cloudflare-accounts-block-websocket-connection/375)

A simple encryption is to use a official signed SSL certificate issued by a certificate authority (for example, [Let’s Encrypt](https://letsencrypt.org/)) to secure communication. You can also consider setting up a proxy with TLS if you prefer a better security setup as well as performance.

---

<div class="post-metadata">

**Author:** ![jesse](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/jesse/32/5168_2.png) [@jesse](https://forum.mattermost.com/u/jesse)\
**Post date:** [April 1, 2019, 2:20pm UTC](https://forum.mattermost.com/t/encryption-used-by-mattermost/6911/6 "2019-04-01T14:20:20Z")

</div>

@vibhi, to comment about need to protect private information: note that Mattermost does not support end-to-end encryption for files nor messages. After verifying the identify of the server (via TLS), Mattermost assumes the user trusts the administrators running that server, as is often the case in workplace environments.

There’s some discussion about this feature request at [https://mattermost.uservoice.com/forums/306457-general/suggestions/36662833-end-to-end-e2e-encryption-support](https://mattermost.uservoice.com/forums/306457-general/suggestions/36662833-end-to-end-e2e-encryption-support).
