<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://blueirissoftware.com/forum/app.php/feed/topic/2093" />

	<title>Blue Iris</title>
	<subtitle>Blue Iris User Group</subtitle>
	<link href="https://blueirissoftware.com/forum/index.php" />
	<updated>2022-02-28T09:08:08+00:00</updated>

	<author><name><![CDATA[Blue Iris]]></name></author>
	<id>https://blueirissoftware.com/forum/app.php/feed/topic/2093</id>

		<entry>
		<author><name><![CDATA[jasestu]]></name></author>
		<updated>2022-02-28T09:08:08+00:00</updated>

		<published>2022-02-28T09:08:08+00:00</published>
		<id>https://blueirissoftware.com/forum/viewtopic.php?p=12787#p12787</id>
		<link href="https://blueirissoftware.com/forum/viewtopic.php?p=12787#p12787"/>
		<title type="html"><![CDATA[Re: Android 3.0 Gotchas]]></title>

		
		<content type="html" xml:base="https://blueirissoftware.com/forum/viewtopic.php?p=12787#p12787"><![CDATA[
Oh, so the app has been updated recently - don't suppose anything changed that could have affected how it handles switching from sub to main streams when zooming in while watching a live camera feed?<br><br><a href="https://blueirissoftware.com/forum/viewtopic.php?f=4&amp;t=3154" class="postlink">https://blueirissoftware.com/forum/view ... f=4&amp;t=3154</a><p>Statistics: Posted by <a href="https://blueirissoftware.com/forum/memberlist.php?mode=viewprofile&amp;u=2754">jasestu</a> — Mon Feb 28, 2022 9:08 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[prd0000]]></name></author>
		<updated>2021-03-24T00:58:25+00:00</updated>

		<published>2021-03-24T00:58:25+00:00</published>
		<id>https://blueirissoftware.com/forum/viewtopic.php?p=8466#p8466</id>
		<link href="https://blueirissoftware.com/forum/viewtopic.php?p=8466#p8466"/>
		<title type="html"><![CDATA[Re: Android Refresh/Update - 3.0.14+]]></title>

		
		<content type="html" xml:base="https://blueirissoftware.com/forum/viewtopic.php?p=8466#p8466"><![CDATA[
Nginx <blockquote class="uncited"><div>Does one need a "valid domain", if they want to stream a cam from BI Android app on a smartphone to a PC on the same LAN with BI and Nginx web server installed? What would be a "valid IP" in this case? Or, is there a simple secure stream solution for that case? What overhead CPU load Nginx causes? <br><br>Is there a lighter secure alternative of the BI Android app? Some use IP Webcam app now, but it doesn't seem to support secure stream on its own.</div></blockquote>Nginx has a very small footprint, and very fast. When you buy a hosting package from hosting provider, they use nginx to share one ip to hundreds of websites. It is used by about 400 million internet sites. And as far as it goes, even ngrok tunnel is heavier than nginx. In my setup, threadripper 2950X with 41 cameras, nginx vm cost me less than 2% cpu overall. And that figure includes 2 native applications (metabase with mongodb, and public website), along with 3 proxies (blueiris, zabbix monitoring, and SAP). <br><br>Valid domain is a must if you want to create third party signed certificate. For internal network, just use non https version. The limitation comes from android.<p>Statistics: Posted by <a href="https://blueirissoftware.com/forum/memberlist.php?mode=viewprofile&amp;u=3052">prd0000</a> — Wed Mar 24, 2021 12:58 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[ramaz16]]></name></author>
		<updated>2021-03-22T22:13:44+00:00</updated>

		<published>2021-03-22T22:13:44+00:00</published>
		<id>https://blueirissoftware.com/forum/viewtopic.php?p=8448#p8448</id>
		<link href="https://blueirissoftware.com/forum/viewtopic.php?p=8448#p8448"/>
		<title type="html"><![CDATA[Re: Android Refresh/Update - 3.0.14+]]></title>

		
		<content type="html" xml:base="https://blueirissoftware.com/forum/viewtopic.php?p=8448#p8448"><![CDATA[
<blockquote class="uncited"><div>A valid domain, and a valid IP. </div></blockquote>Does one need a "valid domain", if they want to stream a cam from BI Android app on a smartphone to a PC on the same LAN with BI and Nginx web server installed? What would be a "valid IP" in this case? Or, is there a simple secure stream solution for that case? What overhead CPU load Nginx causes? <br><br>Is there a lighter secure alternative of the BI Android app? Some use IP Webcam app now, but it doesn't seem to support secure stream on its own.<p>Statistics: Posted by <a href="https://blueirissoftware.com/forum/memberlist.php?mode=viewprofile&amp;u=3747">ramaz16</a> — Mon Mar 22, 2021 10:13 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[prd0000]]></name></author>
		<updated>2021-03-16T23:55:31+00:00</updated>

		<published>2021-03-16T23:55:31+00:00</published>
		<id>https://blueirissoftware.com/forum/viewtopic.php?p=8365#p8365</id>
		<link href="https://blueirissoftware.com/forum/viewtopic.php?p=8365#p8365"/>
		<title type="html"><![CDATA[Re: Android Refresh/Update - 3.0.14+]]></title>

		
		<content type="html" xml:base="https://blueirissoftware.com/forum/viewtopic.php?p=8365#p8365"><![CDATA[
<blockquote class="uncited"><div>The OP suggests to use NGROCK, but it has no Android version. Pls explain in detail, how to use NGROCK installed on Windows PK with an Android smartphone for secure LAN/WAN connection to BI on that PK?<br><br>Do you offer beta testing option for the Android app? Google Play reviews of the app show too many deficiencies at this point. Beta testing can help to fix them much faster. This is a common practice for Android apps development.</div></blockquote>Just use nginx. Install it on blueiris server, and be done. It is free.<p>Statistics: Posted by <a href="https://blueirissoftware.com/forum/memberlist.php?mode=viewprofile&amp;u=3052">prd0000</a> — Tue Mar 16, 2021 11:55 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[ramaz16]]></name></author>
		<updated>2021-03-16T13:51:24+00:00</updated>

		<published>2021-03-16T13:51:24+00:00</published>
		<id>https://blueirissoftware.com/forum/viewtopic.php?p=8361#p8361</id>
		<link href="https://blueirissoftware.com/forum/viewtopic.php?p=8361#p8361"/>
		<title type="html"><![CDATA[Re: Android Refresh/Update - 3.0.14+]]></title>

		
		<content type="html" xml:base="https://blueirissoftware.com/forum/viewtopic.php?p=8361#p8361"><![CDATA[
The OP suggests to use NGROCK, but it has no Android version. Pls explain in detail, how to use NGROCK installed on Windows PK with an Android smartphone for secure LAN/WAN connection to BI on that PK?<br><br>Do you offer beta testing option for the Android app? Google Play reviews of the app show too many deficiencies at this point. Beta testing can help to fix them much faster. This is a common practice for Android apps development.<p>Statistics: Posted by <a href="https://blueirissoftware.com/forum/memberlist.php?mode=viewprofile&amp;u=3747">ramaz16</a> — Tue Mar 16, 2021 1:51 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[prd0000]]></name></author>
		<updated>2021-03-16T23:49:44+00:00 </updated>

		<published>2021-03-16T08:30:10+00:00</published>
		<id>https://blueirissoftware.com/forum/viewtopic.php?p=8355#p8355</id>
		<link href="https://blueirissoftware.com/forum/viewtopic.php?p=8355#p8355"/>
		<title type="html"><![CDATA[Re: Android Refresh/Update - 3.0.14+]]></title>

		
		<content type="html" xml:base="https://blueirissoftware.com/forum/viewtopic.php?p=8355#p8355"><![CDATA[
Hello,<br><br>I think I solved the problem with nginx proxy server. So I think I am going to share what you need to do if you want to follow my steps.<br>Nginx is available on Windows and Linux platform, though I don't use Windows for my web servers. It is a full blown, very small, and very fast web server. Fortunately, it also includes a fast and robust reverse-proxy server.<br><br><strong class="text-strong"><span style="font-size:150%;line-height:116%">A few requirement before we begin:</span></strong><ol style="list-style-type:decimal"><li>A valid domain, and a valid IP. If you have dynamic IP, you can use <a href="https://www.cloudflare.com/" class="postlink">Cloudflare</a> service to keep track whenever your connection changed IP. The instruction to link your dynamic IP to your domain can be found <a href="https://support.cloudflare.com/hc/en-us/articles/360020524512-Manage-dynamic-IPs-in-Cloudflare-DNS-programmatically" class="postlink">here</a></li><li>A third party signed certificate. You can create certificate for free from <a href="https://letsencrypt.org/" class="postlink">Let's Encrypt</a> if you don't have one</li><li><a href="https://nginx.org/en/download.html?_ga=2.122311630.417320390.1615866889-1436194245.1615866889" class="postlink">nginx web server </a>. You can install it on your blueiris server, or into another machine. Your choice. Just open this machine's IP through your router NAT for port 443.</li> </ol><strong class="text-strong"><span style="font-size:150%;line-height:116%">Okay.. now let us begin.</span></strong><ol style="list-style-type:decimal"><li>First, create your certificate chain. It is very easy in nginx. You don't need to care anything about bundle or anything. Just chain all of them in your <strong class="text-strong"><em class="text-italics">server.pem </em></strong>file in the order:<ul><li>YOUR CERTIFICATE</li><li>INTERMEDIATE CERTIFICATE</li><li>ROOT CERTIFICATE</li></ul>For Let's Encrypt, it should look like this.<blockquote class="uncited"><div>-----BEGIN CERTIFICATE-----<br>Subject: CN = mycamera.yourdomain.tld<br>Issuer: C = US, O = Let's Encrypt, CN = R3<br>-----END CERTIFICATE-----<br><br>-----BEGIN CERTIFICATE-----<br>Subject: C = US, O = Let's Encrypt, CN = R3<br>Issuer: C = US, O = Internet Security Research Group, CN = ISRG Root X1<br>-----END CERTIFICATE-----<br><br>-----BEGIN CERTIFICATE-----<br>Subject: C = US, O = Internet Security Research Group, CN = ISRG Root X1<br>Issuer: C = US, O = Internet Security Research Group, CN = ISRG Root X1<br>-----END CERTIFICATE-----</div></blockquote>Except if you use Let's Encrypt, you don't need root certificate. Since ISRG is a known root CA, just put the intermediate one, and you good to go. <br>I'll even make life easier for you.. Here is my certificate.<div class="codebox"><p>Code: </p><pre><code>-----BEGIN CERTIFICATE-----INSERT YOUR CERTIFICATE HERE-----END CERTIFICATE----------BEGIN CERTIFICATE-----MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAwTzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2VhcmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAwWhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3MgRW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cPR5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdxsxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8ZutmNHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxgZ3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaAFHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcwAoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRwOi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQBgt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6WPTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wlikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQzCkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BImlJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1OyK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90IdshCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6ZvMldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqXnLRbwHOoq7hHwg==-----END CERTIFICATE-----</code></pre></div>Save those certificate into <strong class="text-strong"><em class="text-italics">server.pem</em></strong> file.</li><li>Now, we'll edit configuration file. Add these lines at the end of the config file<div class="codebox"><p>Code: </p><pre><code>server {        listen  80;        server_name     mycamera.yourdomain.tld;        location / {               return 301 https://mycamera.yourdomain.tld;        }}server {        listen          443;        server_name     mycamera.yourdomain.tld;        ssl             on;#       ssl_protocols   TLSv1.2 TLSv1.3;        ssl_certificate server.pem;        ssl_certificate_key     server.key;#        access_log      cam-access.log;        location / {                proxy_pass      http://[blue.iris.ip.here]:81;                proxy_buffers   16 4k;                proxy_buffer_size       2k;        }}</code></pre></div>Make sure you put the correct path to your <strong class="text-strong"><em class="text-italics">server.pem</em></strong> and <strong class="text-strong"><em class="text-italics">server.key </em></strong>file. Also put the correct blueiris IP at proxy_pass parameter.<br>The hash sign means that it is disabled. remove the hash to enable it. <ul><li>ssl_protocols is optional, and I prefer to lock it to TLS 1.3 only, hence removing TLSv1.2 option. By default, nginx would response to SSL, TLS 1.1 to 1.3.</li> <li>access_log is also optional, if you want to monitor your activity. But I suggest you disable it when you are done since it could generate significant IO traffic.</li> </ul>Make sure you check the trailing semicolons. Otherwise nginx would complain.<br>I configure it to redirect all http traffic to https by sending 301 permanent redirect.</li> </ol><span style="font-size:150%;line-height:116%">Your server is now configured, and ready to rock.. Now, let's verify your configuration.</span><br><ol style="list-style-type:decimal"><li>Try open it using web browser.. You should see something like these:<div class="inline-attachment"><dl class="file"><dt class="attach-image"><img src="https://blueirissoftware.com/forum/download/file.php?id=1027" class="postimage" alt="secured.jpg" onclick="viewableArea(this);" /></dt></dl></div><div class="inline-attachment"><dl class="file"><dt class="attach-image"><img src="https://blueirissoftware.com/forum/download/file.php?id=1026" class="postimage" alt="camera.jpg" onclick="viewableArea(this);" /></dt></dl></div>If you can open the blue iris login page, you are halfway there. <br><br>Now, to check the chaining, go to <a href="https://decoder.link/sslchecker" class="postlink">SSL Checker</a> to check your chaining. Enter your address, and press CHECK button. You should see something like this:<div class="inline-attachment"><dl class="file"><dt class="attach-image"><img src="https://blueirissoftware.com/forum/download/file.php?id=1028" class="postimage" alt="Screenshot 2021-03-16 150945.jpg" onclick="viewableArea(this);" /></dt></dl></div>The checker will show an error if your chaining is not correct. Just fix it by putting correct sequence at <strong class="text-strong"><em class="text-italics">server.pem</em></strong> file.</li> </ol>When SSL Checker has no chain issues, your blue iris app should work properly now. Make sure you put your URL instead of IP Address in your app. Enjoy.<p>Statistics: Posted by <a href="https://blueirissoftware.com/forum/memberlist.php?mode=viewprofile&amp;u=3052">prd0000</a> — Tue Mar 16, 2021 8:30 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[MikeBwca]]></name></author>
		<updated>2021-02-27T23:08:18+00:00</updated>

		<published>2021-02-27T23:08:18+00:00</published>
		<id>https://blueirissoftware.com/forum/viewtopic.php?p=8170#p8170</id>
		<link href="https://blueirissoftware.com/forum/viewtopic.php?p=8170#p8170"/>
		<title type="html"><![CDATA[Re: Android Refresh/Update - 3.0.14+]]></title>

		
		<content type="html" xml:base="https://blueirissoftware.com/forum/viewtopic.php?p=8170#p8170"><![CDATA[
long press he BI icon.  Select 'App info', or the '!' icon.  Scroll to the bottom.<br><br>You can also go into Settings and tap 'App Info', then scroll to find 'Blue Iris'.<p>Statistics: Posted by <a href="https://blueirissoftware.com/forum/memberlist.php?mode=viewprofile&amp;u=326">MikeBwca</a> — Sat Feb 27, 2021 11:08 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[emerson1vier]]></name></author>
		<updated>2021-02-26T22:41:36+00:00 </updated>

		<published>2021-02-26T22:40:41+00:00</published>
		<id>https://blueirissoftware.com/forum/viewtopic.php?p=8154#p8154</id>
		<link href="https://blueirissoftware.com/forum/viewtopic.php?p=8154#p8154"/>
		<title type="html"><![CDATA[Re: Android Refresh/Update - 3.0.14+]]></title>

		
		<content type="html" xml:base="https://blueirissoftware.com/forum/viewtopic.php?p=8154#p8154"><![CDATA[
How can I see my app version on Android?<p>Statistics: Posted by <a href="https://blueirissoftware.com/forum/memberlist.php?mode=viewprofile&amp;u=1749">emerson1vier</a> — Fri Feb 26, 2021 10:40 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[varghesesa]]></name></author>
		<updated>2021-02-26T22:17:33+00:00</updated>

		<published>2021-02-26T22:17:33+00:00</published>
		<id>https://blueirissoftware.com/forum/viewtopic.php?p=8153#p8153</id>
		<link href="https://blueirissoftware.com/forum/viewtopic.php?p=8153#p8153"/>
		<title type="html"><![CDATA[Android 3.0 Gotchas]]></title>

		
		<content type="html" xml:base="https://blueirissoftware.com/forum/viewtopic.php?p=8153#p8153"><![CDATA[
<span style="font-size:150%;line-height:116%"><strong class="text-strong">Introduction</strong></span><br>This article is from BI support in order get known issues and fixes to the community as soon as possible.<br><br>We did a complete refresh of the Android app on Feb. 12, 2021, starting with version 3.0.14.  We appreciate all feedback and are vigilant in incorporating the feedback and bug fixes into the product asap.<br><br>Never a bad idea to reset the phone and the app: delete data, cache, reinstall the app and see if functionality returns or issues goes away.<br><br><br><br><span style="font-size:150%;line-height:116%"><strong class="text-strong">Known Issues</strong></span><br><br><strong class="text-strong"><span style="text-decoration:underline">Override Do not Disturb for BI app notifications.</span></strong><div style="margin-left:3em">Some users prefer to have their Do Not Disturb (DnD) settings overridden by the BI app, i.e. if a BI alert happens late at night, users still want to be notified.<br><br>The Android settings that allow you to override DnD will only apply to the "default" notification sound.   We cannot support it when using custom notification sounds, as each notification category can only have one custom sound, where our system allows multiple custom sounds.   This is a limitation of Android.<br><br>Users that need to override DnD should use the default notification sound.<br><br><br></div><strong class="text-strong"><span style="text-decoration:underline">Setting up geofencing</span></strong><div style="margin-left:3em">We made more changes in order to make it easy for users to setup geofencing!<br>Easiest way is to Create a New Server -&gt; Go through the App Wizard -&gt; Following geofencing instructions.  Delete your current server after new server is setup correctly.<br><br><br> </div><strong class="text-strong"><span style="text-decoration:underline">Below is a list of settings that may or may not apply to your phone that could affect geo-fencing accuracy.</span></strong><div style="margin-left:3em"><ul><li>Make sure battery optimization is off.</li><li><strong class="text-strong">WiFi must be turned on.</strong> It may seem weird, but the low power location management that Geofencing uses is actually primarily based off distances from WiFi signals.</li><li>Go to your device's Settings, navigate to your Location Settings.  Make sure that your phone's <strong class="text-strong">Location is turned on</strong> and also in <strong class="text-strong">High Accuracy Mode</strong>.</li><li>Make sure that your device has given the app Location Permission (on Android 10 and higher, you will need to give location permission <strong class="text-strong">"All the time"</strong>)</li><li><strong class="text-strong">Newer devices put applications to sleep if they haven't been opened in a while.</strong>  It is difficult to determine if your device has a setting for this or not.  You will have to look through your phone settings to see.  For example, the latest Samsung devices use the Smart Manager to put our app to sleep.  To add our app to the unmonitored list on a Samsung, go to Settings -&gt; Battery -&gt; Unmonitored Apps -&gt; then add Simple In/Out to the list.</li><li>The phone <strong class="text-strong">must have mobile data</strong>.  Geofences will not work without an internet connection.</li><li>The phone <strong class="text-strong">must NOT be in Airplane Mode</strong>.  Airplane Mode will disable both WIFI and Location.</li><li><strong class="text-strong">Avoid using 'Power Saving Mode'</strong> while using Geofences.  The Geofences will be a lot less consistent while Power Saving Mode is turned on (as it will automatically lower your location accuracy).</li><li><strong class="text-strong">Avoid using 'Task Killer' apps on your phone</strong>.  Task killer apps can potentially kill the background processes that monitor the Geofences.  Any application that has the ability to kill, stop, or sleep our application may prevent Geofences from working.</li></ul>User feedback regarding geo-fencing on Android devices:<ul><li>Is there a problem with Samsung devices and the geofence function, because I have never got it to work well, this is my third Samsung phone. <br> When I had a iphone 6 there was no problem with geofence.<br><br>My Blueiris application has access to the location service all the time.  The location (lat/lon) in BlueIris server setting is set up to where I live.  When I check my location in a GPS tool on the phone it is within the range to be inside, but it still says I am outside.  I have tried to reset the Geofence location in the app.  Removed and added my device in Blueiris.  Changed the Lat/Lon settings in the app.<br><br>Also, If I set the profile to be inside anyway it keeps the profile but when I check the device status it says I am outside of the Geofence.<br><br><strong class="text-strong">Newer versions of Android have more aggressive battery saving measures.   This can affect the frequency at which location updates are triggered. Try disabling any battery optimizations for the app.  It's also important that the app's location permission is set to "allow all the time" and not "allow when app is open".<br><br>Nothing more we can do on the app side.  We react to the location and if the device reports a geolocation outside of the geofence, a transition is triggered.  Expanding the radius may help.<br><br>If geo-fence is not working for you, BI provides alternative solutions, albeit less convenient.  For example, you could simply use the app as a remote control device.  When you walk into the house or pull into the garage, you could manually switch the profile and vice versa when leaving.<br><br>Other users use the shield icon, which mimics the arm/disarm feature that you see on home surveillance solutions like ADT.<br></strong></li></ul><br><br>Geofence Gotcha1:  You allowed the BI app location services yet the App continues to state permission denied.<br><div class="inline-attachment"><dl class="file"><dt class="attach-image"><img src="https://blueirissoftware.com/forum/download/file.php?id=1784" class="postimage" alt="android gotchas_geo gotcha1.png" onclick="viewableArea(this);" /></dt></dl></div>The user needs to figure out how to "allow all the time" with their particular Android device.   An uninstall / reinstall should allow them to go through the initial steps again.<br><br><br></div><strong class="text-strong"><span style="text-decoration:underline">3.0.22: Notification settings not working.  Sound alerts keep playing the default sound only</span></strong><div style="margin-left:3em">In Settings, Users can now adjust the sound, LED and vibrate notifications.<br>If you want to go back to default settings, simply select "Choose Default Notification Options".<br><div class="inline-attachment"><dl class="file"><dt class="attach-image"><img src="https://blueirissoftware.com/forum/download/file.php?id=1015" class="postimage" alt="notification settings.jpg" onclick="viewableArea(this);" /></dt></dl></div><br>Fix: The user needs to figure out how to "allow all the time" with their particular Android device.   An uninstall / reinstall should allow them to go through the initial steps again.<br><br><br></div><strong class="text-strong"><span style="text-decoration:underline">Can I roll back to the previous version?</span></strong><div style="margin-left:3em">It may be possible to continue to run the old app which Google already approved, however we do not have this APK for distribution.  We are very responsive to feedback and fix issues asap.  <br><br><br></div><strong class="text-strong"><span style="text-decoration:underline">What happened to the cast icon?</span></strong><div style="margin-left:3em">Chromecast sends the video stream to a Cast-enabled device.  It's still there, but Android seems to have tighter restrictions similar to SSL certificates as described above.<br><br>The Chromecast button will show up in the top bar for a video if:<ol style="list-style-type:decimal"><li>One of your two connections (LAN/WAN) is HTTPS.</li><li>The video you're looking to cast has audio.</li><li>The video you're looking to cast is not multi-cam.</li><li>The video is a live stream.</li></ol><br></div><strong class="text-strong"><span style="text-decoration:underline">In the Camera tab, when I view a group, I cannot select a camera in the group. To view the desired camera, I must scroll through the list and select it.</span></strong><div style="margin-left:3em">Longpress camera in group to open camera</div><br><br><strong class="text-strong"><span style="text-decoration:underline">SSL certificates / <a name="TLS">TLS</a></span></strong><div style="margin-left:3em"><br>Are you using TLS or certificates?<br><br><strong class="text-strong">Self signed certs are no longer allowed within Android, so users will need to get a properly signed certificate in order to leverage HTTPS connections.</strong>  <br><br>You may want to reconsider whether encryption is needed for your cameras.  Blue Iris DOES already encrypt login credentials.  Your password and session are secure WITHOUT using HTTPS or Stunnel.  The video itself is ENCODED only, so it may be POSSIBLE for a malicious ISP or government agency to spy on your video, but it's safe from general "hacking".  You can turn off Stunnel on the Settings/Web server page in the PC and the issue will resolve.  <br><br>If you really want full HTTPS security on the app, please consider using NGROK instead, it's just much more straightforward than dealing with Stunnel and certificates etc.<br><br>However, if you want to proceed with Stunnel, continue reading.<br><br>Others users have stated they are using a public key.  <strong class="text-strong">However, Android decides which CA authorities are valid, not BI.  There is nothing we can do from the app side to force Android to trust a user's CA.  Either they do or they don't.</strong>  In fact, we were removed from the Play Store for ignoring errors and forcing Android to accept that connection.  More details here.  <a href="https://developer.android.com/training/articles/security-ssl.html#CommonProblems" class="postlink">https://developer.android.com/training/ ... onProblems</a><br><br>The Android team is using a PositiveSSL cert from Namecheap.com.  Other CA Authorities include ZeroSSL or GoDaddy.  The SSL and HTTPS section in Help also has information regarding using SSL with a domain in order to work with Android.<br><br>For the java exception, "CertPathValidatorException: Trust anchor for certification path not found.", per the docs, this is caused by:<br><ol style="list-style-type:decimal"><li>Using an unknown certificate authority and/or a self signed cert</li><li>A missing intermediate certificate authority.</li></ol><strong class="text-strong">Missing Intermediate Certificates Authority</strong><br>Google says the solution is "Configure the server to include the intermediate CA in the server chain. Most CAs provide documentation on how to do this for all common web servers."<br><br><span style="text-decoration:underline"><em class="text-italics">User 1 example: namecheap.com (Sectigo)</em></span><br>From another user, who got his certificate from Sectigo (previously Comodo) through namecheap.com (as well).  Some slight changes to the STunnel config as seen below (obfuscated):<br>[blue-iris]<br>accept = ##<br>connect = xxx.xxx.xxx.xxx:##<br>CAfile = certname.ca-bundle    (had to add this line for the intermediary stuff I think)<br>cert = certname.pfx<br><br><br><span style="text-decoration:underline"><em class="text-italics">User 2 example: pfSense CA</em></span><br>Simply created a new intermediate CA (on same pfSense install) signed by my original pfSense CA and then from that intermediate CA created a new Server Certificate for my BlueIris stunnel config.<br><br>I created a new .pem for the new cert and replaced the existing entry in my stunnel config, so I only needed to change the cert entry:<br><br>[blueiris]<br>accept = 8443<br>connect = 127.0.0.1:9443<br>cert = Iris10IntermediateCA.pem<br><br>The new Iris10IntermediateCA.pem is formatted just the same as the original:<div class="codebox"><p>Code: </p><pre><code>-----BEGIN CERTIFICATE-----MIIERzCC……lW9xMlNg==-----END CERTIFICATE----------BEGIN PRIVATE KEY-----MIIEvwIB……BGDO7i4ng==-----END PRIVATE KEY-----</code></pre></div>I also needed to trust (i.e. install) the new intermediate CA certificate onto my Android phone using the system settings UI flow. I’d have to do the same for every other Android phone/tablet we use with the BI app.<br><br><br><em class="text-italics"><span style="text-decoration:underline">User 3 example: Let's encrypt service</span></em><br>I followed the instructions from letsencrypt which consists of:<ul><li>Download and install the certbot client</li><li>On the BI machine run windows cmd : $ certbot certonly— standalone.  It asks several inputs like domain name etc.  Follow the process and this will generate 2 files privKey1.pem and fullchain1.pem</li><li>Declare the 2 generated files in stunnel config file :<br>cert=/etc/letsencrypt/live/example.com/fullchain1.pem<br>key=/etc/letsencrypt/live/example.com/privkey1.pem</li><li>Restart Stunnel and it works well.</li></ul>Lets encrypt is free but the certificate will expire after 3 months.<br>Automatic renewal is also possible to setup. I didn't do it at this stage.<br><br>Another Let's encrypt user stated:<br><br>Thank you, I read the page (this article) and found out all I need is to put the certificate and private key in separate files instead of one pem file.<br><br><br><em class="text-italics"><span style="text-decoration:underline">User 4 example: ZeroSSL service</span></em><ul><li>Use ZeroSSL to generate a CA-signed certificate. Certificates with 3-month durations are free.</li><li>Download the certificate from ZeroSSL. This is a ZIP file containing the following files:<div class="codebox"><p>Code: </p><pre><code>ca_bundle.crtcertificate.crtprivate.key</code></pre></div></li><li>Rename private.key to key.pem and move it into the stunnel configuration folder (default location is C:\Program Files (x86)\stunnel\config).</li><li>It looks like Android requires the full certificate chain, including the root certificate, which is not provided by ZeroSSL by default. Their website's help section says the following: "If you need the full chain including the root certificate we recommend you use a tool like whatsmychaincert.com to download it". So, go to <a href="https://whatsmychaincert.com" class="postlink">https://whatsmychaincert.com</a>, enter your server's public IP address, and download the file containing the full chain.</li><li>Rename this file to <strong class="text-strong">cert.pem</strong> and move it into the stunnel config folder.</li><li>Edit the Blue Iris section of the stunnel config file to include both files as follows:<div class="codebox"><p>Code: </p><pre><code>cert = cert.pemkey = key.pem</code></pre></div></li><li>Restart stunnel and the Android app should connect successfully via HTTPS.</li></ul><em class="text-italics"><span style="text-decoration:underline">DDNS &amp; STunnel Gotcha</span></em><br>Since I was using a DDNS to point to my host that I had to use the DDNS rather than the external IP.  STUNNEL will only recognize the DDSN name and not the external IP.<br><br><em class="text-italics"><span style="text-decoration:underline">User 5 example: No-IP DDNS + Let's Encrypt ssl</span></em><br>stunnel.pem file was composed of my key file and my crt file. It also needed the chain file appended to the end of it. <br>So my stunnel config uses stunnel.pem as the cert file.<br><br>Not working: mydomain-key.pem + mydomain-crt.pem concatenated into stunnel.pem<br>Working: mydomain-key.pem + mydomina-crt.pem + mydomain-chain.pem concatenated into stunnel.pem<br><br><br><em class="text-italics"><span style="text-decoration:underline">Troubleshooting Certificates</span></em><br><br>If the above examples do not help resolve your certificate issue, this user was kind enough to document how he resolved the issue.<br><blockquote class="uncited"><div>I went to <a href="https://www.geocerts.com/ssl-checker" class="postlink">https://www.geocerts.com/ssl-checker</a> and put in my domain name <a href="http://www.cohovideofeed.com" class="postlink">www.cohovideofeed.com</a>.<br>That site will tell you the problem.<br>I got the error:<br><br>A valid Root CA Certificate could not be located, the certificate will likely display browser warnings.<br><br>Had to add Root certificate and it had to be in the correct order.<br><br><span style="text-decoration:underline">Chaining certificates correctly</span><br><br>Some web servers need all SSL/TLS (root, intermediate and end-user) certificates in <strong class="text-strong">one file</strong> but CAs normally send you all their certificates separated, so you need to concatenate them manually. But pay attention while concatenating them because their order is important!<br>The correct order of a chained certificate is:<br><br>1.  end-user certificate<br>2.  all intermediate certificates<br>3.  root certificate<br><br>I also had to add these lines:<br>sslVersionMax = TLSv1.2<br>sslVersion = TLSv1.2<br><br>Works great now</div></blockquote></div><p>Statistics: Posted by <a href="https://blueirissoftware.com/forum/memberlist.php?mode=viewprofile&amp;u=521">varghesesa</a> — Fri Feb 26, 2021 10:17 pm</p><hr />
]]></content>
	</entry>
	</feed>
