> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/administradores/web.md).

# Web server

Editran Connect uses an integrated web server based on **nginx**, installed alongside the solution. This component serves the web interface over HTTPS and acts as a reverse proxy to the system's internal web services.

***

## Configuration file location

* File path: `<ruta_instalacion_connect>\server\nginx.conf`
* Certificate path:
  * Certificate: `<ruta_instalacion_connect>\server\certs\editran.pem`
  * Private key: `<ruta_instalacion_connect>\server\certs\editran.key`
* Web content root: `<ruta_instalacion_connect>\EditranConnect\web`, Connect web app.

### Ports used

| Port | Protocol | Exposed service                     |
| ---- | -------- | ----------------------------------- |
| 443  | HTTPS    | Main web interface (nginx)          |
| 8081 | HTTP     | Functional backend (`connect-back`) |
| 8085 | HTTP     | Signing service (`editranff`)       |

### Configured routes

| Route           | Type          | Internal destination                 |
| --------------- | ------------- | ------------------------------------ |
| `/`             | Static        | `web/index.html`                     |
| `/connect-back` | Reverse proxy | `http://localhost:8081/connect-back` |
| `/editranff`    | Reverse proxy | `http://localhost:8085/editranff`    |
| `/50x.html`     | Error page    | `html/50x.html`                      |

### TLS security

| Parameter           | Value                                |
| ------------------- | ------------------------------------ |
| Enabled protocols   | TLSv1.2, TLSv1.3                     |
| Allowed ciphers     | HIGH:!aNULL:!MD5                     |
| Cipher preference   | Forced by the server (on)            |
| SSL session timeout | 5 minutes (`ssl_session_timeout 5m`) |

### Important files

| File         | Description                           |
| ------------ | ------------------------------------- |
| `nginx.conf` | Main server configuration             |
| `index.html` | Main page of the web application      |
| `50x.html`   | Page shown for 500/502/503/504 errors |

### Administrative considerations

* The server listens only on port 443 with SSL enabled.
* The Java services are not directly exposed; they are only accessible through nginx.
* Any modification to `nginx.conf` requires restarting nginx to apply the changes.
* It is recommended to check the validity of the configuration before restarting with the following command:

```bash
nginx.exe -t
```

> ⚠️ Important: Do not directly modify nginx.conf without making a backup. Ensure the validity of the installed certificates and the availability of the configured ports.

***

## Replacing SSL certificates in nginx

The Editran Connect web server uses local certificates installed by default. For production environments, it is recommended to replace them with your own more secure certificates, issued by a trusted certificate authority (CA) or managed automatically using your trusted tool for this purpose.

> ⚠️ **Important note:**\
> Given the wide range of available SSL certificates, their technical variants (RSA, ECDSA, ECC, Ed25519, etc.), and the rapid evolution of TLS security recommendations, **this manual does not cover in detail the configuration of all possible scenarios**.
>
> For updated guidance, it is recommended to consult directly the [official nginx documentation](https://nginx.org/en/docs/http/configuring_https_servers.html) and use reference tools such as the [Mozilla SSL Configuration Generator](https://ssl-config.mozilla.org/).
>
> The sole purpose of this section is to point out the **key settings that should be reviewed** when replacing the certificates with ones other than those installed by default.

### Key consideration: the certificate type affects SSL directives

When changing the certificate, it is not only the files that change. Other aspects may also change, such as:

* The algorithm (RSA, ECDSA, Ed25519…)
* The TLS protocol that supports it (1.2 vs 1.3)
* The compatible cipher suites

Therefore, **the nginx configuration must be adapted to the new certificate** so that it is effective and secure.

### What should be reviewed when using a different certificate?

1. **Key algorithm**
   * If you use a certificate **ECDSA**, you will need to keep specific suites enabled for `ECDHE-ECDSA`.
   * If you use a certificate **RSA**, nginx will use suites `ECDHE-RSA`, `DHE-RSA`, etc.
   * Some environments allow combining both certificates (`ssl_certificate` + `ssl_certificate_ecdsa`).
2. **TLS protocols**
   * Modern certificates (such as Let's Encrypt ECC) may require enabling **only TLS 1.2 and 1.3**.
   * Make sure that `ssl_protocols` is aligned with the certificate: `conf ssl_protocols TLSv1.2 TLSv1.3;`
3. **Cipher suites**
   * The directives `ssl_ciphers` must allow the algorithms compatible with your certificate.
   * See the corresponding section:
     * <https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_ciphers>
4. **Optional additional parameters**

   * If you use elliptic curve keys (ECDSA), consider reviewing or explicitly defining:

   ```conf
   ssl_ecdh_curve secp384r1;
   ```

   * You can add:

   ```conf
   ssl_certificate_key_file_type rsa;
   ```

   If nginx does not detect it correctly (version-dependent).

***

### Documentation and testing

To adapt the configuration correctly to your certificate, you can consult:

* [nginx: ssl\_certificate](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate)
* [ssl\_ciphers and support by certificate type](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_ciphers)
* [Mozilla SSL Config Generator](https://ssl-config.mozilla.org/)

## Temporary folders of other users in nginx

The standard nginx server configuration included in our environments is designed for secure use within the private premises of customers' intranets. As part of its normal operation, nginx automatically creates several temporary directories at runtime within:

```txt
<ruta_instalacion_connect>/server
```

It is common for these directories to belong to different system users, such as:

* nginx
* www-data
* nobody

### Possible temporary directories

During execution, folders such as:

* temp\_proxy
* temp\_fastcgi
* temp\_scgi
* temp\_uwsgi
* temp\_client\_body

These folders are used internally by nginx to manage buffers, incoming requests, and intermediate web server processes.

> ⚠️ **Important warning**
>
> **Do not modify the owners or groups (users/groups) of these directories.** Altering their permissions or ownership can cause the web server to malfunction and directly affect the application's performance and stability.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/administradores/web.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
