> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/firma/requisitos_y_puesta_en_marcha.md).

# Requirements and getting started

The signing functionality of Connect is divided between two scenarios: server and workstation from which the signature is requested. Each of these scenarios must be prepared as described below.

**Server requirements**

* **Install** the product in web mode.
* Have a license that includes the signing feature.
* The **Editran Connect Sign service** must be started.
* Traffic through the **port** on which the web service is raised must be open. Check that port in the configuration file `server/conf/nginx.conf` (block `server`, parameter `listen`). The default value of this port is `443`.
* So that https connections to the web server do not show trust issues (this is how signers will connect to the application from their machines), the **SSL certificate** included in the product must be replaced by an SSL certificate issued by a Certificate Authority recognized for the `machine/domain/subdomain` of the Connect web server. For more information on the use and configuration of nginx in Connect, consult the section [Notes and Tips for Administrators](/documentacion-editran/connect-v2.1-en/administradores.md).
* Perform all **signing configuration and administration** of **Connect** necessary. Consult [Connect Signature Administration](https://gitlab.devops.onesait.com/onesait/disruptors/ecosystems-editran/editran-documentation/-/blob/develop/connect/2.1/firma/administracionconnectfirma/README.md). The public part of each certificate that will be used for signing (extension .cer) is part of the configuration of the users with signer role they represent, so those certificates must be available and accessible on the server at the time of that configuration.
* The **files** to be signed will be hosted in directories on the server where Connect has been installed or on network resources that are accessible from the product.

**Signing workstation requirements**

A signing workstation is any device from which Connect will be accessed for the purpose of performing signatures. The users who will access from these workstations will have the signer role in Connect.

* **Private key certificates**: the certificates with which the accessing user will perform the signatures must be properly installed in the machine's personal certificate store. These certificates have the extension *.pfx* or *.p12*.\
  It is recommended to apply the high protection level when installing private key certificates on machines so that the password protecting the private key is requested before each signature is made.\
  The certificates that must be installed are those corresponding to the public key certificates that have been configured for the user in Connect.\
  If cloud certificates are going to be used, the user must previously log in to the corresponding provider agent (CSP) so that the certificate appears available in that store at the time of signing.
* **Connection URL**: the users with signer role registered in the product will connect from their machines to the web server where Connect has been deployed by typing the address `https://server_ip` (or `https://server_ip:port`, if in the parameter *listen* of the server block of the configuration file `server/conf/nginx.conf` a port different from the `443`).
* **Desktop application**: signatures are performed with a desktop application that must be properly installed and configured on each signing workstation before the first signature is made. During the installation process of this application the server where Connect is deployed is indicated (`server_ip/hostname`) and the listening port of the **Editran Connect Sign** service on that server (by default this port is `8085`). The installer for this application can be downloaded the first time a signature request is initiated from a window that offers the link or, alternatively, obtained manually from the directory `signs/app` of the Connect installation on the server workstation to bring it to each signing workstation. Everything related to this application is described in detail in [Installation of the desktop application on signing workstations](https://gitlab.devops.onesait.com/onesait/disruptors/ecosystems-editran/editran-documentation/-/blob/develop/connect/2.1/firma/firmadeficheros/detallefichero/firmar/README.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/firma/requisitos_y_puesta_en_marcha.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
