> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/administradores/web.md).

# Web server

Editran Connect uses an integrated web server based on **nginx**, installed together with the solution. This component serves the web interface via HTTPS and acts as a reverse proxy to the system's internal web services.

***

## Configuration file location

* File path: `<installation_path_connect>\server\nginx.conf`
* Certificates path:
  * Certificate: `<installation_path_connect>\server\certs\editran.pem`
  * Private key: `<installation_path_connect>\server\certs\editran.key`
* Web content root: `<installation_path_connect>\EditranConnect\web`, connect webapp.

### Ports used

| Port | Protocol | Exposed service                     |
| ---- | -------- | ----------------------------------- |
| 443  | HTTPS    | Main web interface (nginx)          |
| 8081 | HTTP     | Functional backend (`connect-back`) |
| 8085 | HTTP     | Signing service (`editranff`)       |

### Configured routes

| Path            | Type          | Internal destination                 |
| --------------- | ------------- | ------------------------------------ |
| `/`             | Static        | `web/index.html`                     |
| `/connect-back` | Reverse proxy | `http://localhost:8081/connect-back` |
| `/editranff`    | Reverse proxy | `http://localhost:8085/editranff`    |
| `/50x.html`     | Error page    | `html/50x.html`                      |

### TLS security

| Parameter           | Value                                |
| ------------------- | ------------------------------------ |
| Enabled protocols   | TLSv1.2, TLSv1.3                     |
| Allowed ciphers     | HIGH:!aNULL:!MD5                     |
| Cipher preference   | Enforced by the server (on)          |
| SSL session timeout | 5 minutes (`ssl_session_timeout 5m`) |

### Important files

| File         | Description                           |
| ------------ | ------------------------------------- |
| `nginx.conf` | Main server configuration             |
| `index.html` | Main page of the web application      |
| `50x.html`   | Page shown for 500/502/503/504 errors |

### Administrative considerations

* The server listens only on port 443 with SSL enabled.
* Java services are not directly exposed; they are only accessible through nginx.
* Any modification in `nginx.conf` requires restarting nginx to apply the changes.
* It is recommended to check the validity of the configuration before restarting with the following command:

```bash
nginx.exe -t
```

> ⚠️ Important: Do not modify nginx.conf directly without making a backup. Ensure the validity of the installed certificates and the availability of the configured ports.

***

## Replacing SSL certificates in nginx

The Editran Connect web server uses local certificates installed by default. For production environments, it is recommended to replace them with more secure custom certificates, issued by a trusted certificate authority (CA) or managed automatically by your trusted tool for that purpose.

> ⚠️ **Important note:**\
> Given the wide range of available SSL certificates, their technical variants (RSA, ECDSA, ECC, Ed25519, etc.) and the rapid evolution of TLS security recommendations, **this manual does not cover in detail the configuration of all possible scenarios**.
>
> For up-to-date guidance, it is recommended to consult the [official nginx documentation](https://nginx.org/en/docs/http/configuring_https_servers.html) and use reference tools such as the [Mozilla SSL Configuration Generator](https://ssl-config.mozilla.org/).
>
> This section has the sole purpose of pointing out the **key settings that should be reviewed** when replacing the default installed certificates with others.

### Key consideration: the certificate type affects SSL directives

When changing the certificate, not only the files change. Aspects such as the following may also change:

* The algorithm (RSA, ECDSA, Ed25519…)
* The TLS protocol that supports it (1.2 vs 1.3)
* The compatible cipher suites

Therefore, **the nginx configuration must be adapted to the new certificate** so that it is effective and secure.

### What to review when using a different certificate?

1. **Key algorithm**
   * If you use a certificate **ECDSA**, you will need to keep specific suites enabled for `ECDHE-ECDSA`.
   * If you use a certificate **RSA**, nginx will use `ECDHE-RSA`, `DHE-RSA`etc.
   * Some environments allow combining both certificates (`ssl_certificate` + `ssl_certificate_ecdsa`).
2. **TLS protocols**
   * Modern certificates (such as Let's Encrypt ECC ones) may require enabling **only TLS 1.2 and 1.3**.
   * Make sure that `ssl_protocols` is aligned with the certificate: `conf ssl_protocols TLSv1.2 TLSv1.3;`
3. **Cipher suites**
   * The directives `ssl_ciphers` must allow the algorithms compatible with your certificate.
   * Check the corresponding section:
     * <https://nginx.org/en/docs/http/ngx\\_http\\_ssl\\_module.html#ssl\\_ciphers>
4. **Optional additional parameters**

   * If you use curve keys (ECDSA), consider reviewing or explicitly defining:

   ```conf
   ssl_ecdh_curve secp384r1;
   ```

   * You can add:

   ```conf
   ssl_certificate_key_file_type rsa;
   ```

   If nginx does not detect it correctly (version dependent).

***

### Documentation and tests

To correctly adapt the configuration to your certificate, you can consult:

* [nginx: ssl\_certificate](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate)
* [ssl\_ciphers and support by certificate type](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_ciphers)
* [Mozilla SSL Config Generator](https://ssl-config.mozilla.org/)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/administradores/web.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
