> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/firma/requisitos_y_puesta_en_marcha.md).

# Requirements and deployment

The Connect signing functionality is split between two scenarios: server and the workstation from which the signature is requested. Each of these scenarios must be prepared as described below.

**Server requirements**

* **Install** the product in web mode.
* Have a license that includes the signature feature.
* The **Editran Connect Sign service** must be running.
* Traffic through the **port** on which the web service is started must be open. Check said port in the configuration file `server/conf/nginx.conf` (block `server`, parameter `listen`). The default value of this port is the `443`.
* For HTTPS connections to the web server not to show trust issues (thus the signers will connect to the application from their own computers), the **SSL certificate** included in the product must be replaced with an SSL certificate issued by a recognized Certification Authority for the `machine/domain/subdomain` of the Connect web server. For more information on the use and configuration of nginx in Connect, see the section [Notes and Tips for Administrators](/documentacion-editran/connect-3.2-en/administradores.md).
* Carry out all the **signature configuration and administration** of **Connect** needed. See [Connect Signature Administration](https://gitlab.devops.onesait.com/onesait/disruptors/ecosystems-editran/editran-documentation/-/tree/public/connect/3.2/firma/administracionconnectfirma/README.md).
  * The public part of each certificate that will be used for signing (.cer extension) is part of the configuration of the users with signer role they represent, so these certificates must be available and accessible on the server at the time of said configuration.
  * If signatures are going to be made with private key certificates hosted by a cloud signature provider whose integration with Connect is implemented:
    * Carry out the configuration of that integration.
    * Outbound connectivity via HTTPS (port 443) to the provider's services.
* The **files** to be signed will be stored in directories on the server where Connect has been installed or in network resources accessible from the product.

**Signer workstation requirements**

Signer workstation is any computer or device from which Connect will be accessed in order to carry out signatures. The users who will access from these workstations will have signer role in Connect.

* **Private key certificates**: the certificates with which the user accessing will perform the signatures will be those corresponding to the public key certificates that have been configured for the user with signer role in Connect.
  * The location of the private key certificates (Windows personal certificate store or cloud) and the operating system from which the signing process is initiated determine how it is carried out, whether with the desktop application or in the cloud.
  * These certificates have extension *.pfx* or *.p12*.
  * For certificates installed in Windows, it is recommended to apply the high protection level during installation on the computers so that the password protecting the private key is requested before each signature is made.
  * If cloud certificates are going to be used through CSP in Windows, the computer must have the corresponding provider's agent and the user must log in to it beforehand so that the certificate appears available in the Windows certificate store at the time of signing.
  * Certificates whose configuration indicates that one of their locations will be the cloud of a certain provider must be properly stored there.
* **Connection URL address**: users with signer role registered in the product will connect from their devices to the web server where Connect has been deployed by typing the address `https://server_ip` (or `https://server_ip:port`, if in the parameter *listen* of the server block of the configuration file `server/conf/nginx.conf` a port different from the `443`).
* **Desktop application**: if certificates located in the Windows certificate store are going to be used, and this has been indicated in the configuration of the user with signer role, this application must be properly installed and configured on the workstation of that operating system before the first signature is made. During the installation process of this application, the server where Connect is deployed is indicated (`server_ip/hostname`) and the service listening port **Editran Connect Sign** on said server (by default this port is `8085`). The installer for this application can be downloaded the first time a signature request is initiated from a window that offers the link or, alternatively, obtained manually from the directory `signs/app` of the Connect installation on the server workstation to take it to each signer workstation. Everything related to this application is described in detail in [Installation of the desktop application on signer workstations](/documentacion-editran/connect-3.2-en/firma/firmadeficheros/detallefichero/firmar/firma_cert_windows.md#instalacion-de-la-aplicacion-de-escritorio-en-los-puestos-firmantes).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/firma/requisitos_y_puesta_en_marcha.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
