> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/administradores/web.md).

# Web server

Editran Connect uses an integrated web server based on **nginx**, installed together with the solution. This component serves the web interface over HTTPS and acts as a reverse proxy to the system's internal web services.

***

## Configuration file location

* File path: `<ruta_instalacion_connect>\server\nginx.conf`
* Certificate path:
  * Certificate: `<ruta_instalacion_connect>\server\certs\editran.pem`
  * Private key: `<ruta_instalacion_connect>\server\certs\editran.key`
* Web content root: `<ruta_instalacion_connect>\EditranConnect\web`, Connect webapp.

### Ports used

| Port | Protocol | Exposed service                     |
| ---- | -------- | ----------------------------------- |
| 443  | HTTPS    | Main web interface (nginx)          |
| 8081 | HTTP     | Functional backend (`connect-back`) |
| 8085 | HTTP     | Signature service (`editranff`)     |

### Configured routes

| Route           | Type          | Internal destination                 |
| --------------- | ------------- | ------------------------------------ |
| `/`             | Static        | `web/index.html`                     |
| `/connect-back` | Reverse proxy | `http://localhost:8081/connect-back` |
| `/editranff`    | Reverse proxy | `http://localhost:8085/editranff`    |
| `/50x.html`     | Error page    | `html/50x.html`                      |

### TLS security

| Parameter           | Value                                |
| ------------------- | ------------------------------------ |
| Enabled protocols   | TLSv1.2, TLSv1.3                     |
| Allowed ciphers     | HIGH:!aNULL:!MD5                     |
| Cipher preference   | Forced by the server (on)            |
| SSL session timeout | 5 minutes (`ssl_session_timeout 5m`) |

### Important files

| File         | Description                           |
| ------------ | ------------------------------------- |
| `nginx.conf` | Main server configuration             |
| `index.html` | Main page of the web application      |
| `50x.html`   | Page shown for 500/502/503/504 errors |

### Administrative considerations

* The server listens only on port 443 with SSL enabled.
* Java services are not directly exposed; they are only accessible through nginx.
* Any modification in `nginx.conf` requires restarting nginx to apply the changes.
* It is recommended to verify the validity of the configuration before restarting with the following command:

```bash
nginx.exe -t
```

> ⚠️ Important: Do not modify nginx.conf directly without making a backup. Ensure the validity of the installed certificates and the availability of the configured ports.

***

## Replacing SSL certificates in nginx

Editran Connect's web server uses local certificates installed by default. For production environments, it is recommended to replace them with your own more secure certificates, issued by a trusted certificate authority (CA) or automatically managed using your trusted tool for this purpose.

> ⚠️ **Important note:**\
> Given the wide range of available SSL certificates, their technical variants (RSA, ECDSA, ECC, Ed25519, etc.) and the rapid evolution of TLS security recommendations, **this manual does not cover in detail the configuration of all possible scenarios**.
>
> For updated guidance, it is recommended to consult directly the [official nginx documentation](https://nginx.org/en/docs/http/configuring_https_servers.html) and use reference tools such as the [Mozilla SSL Configuration Generator](https://ssl-config.mozilla.org/).
>
> The sole purpose of this section is to point out the **key settings that should be reviewed** when replacing the certificates with others different from the default installed ones.

### Key consideration: the certificate type affects SSL directives

When changing the certificate, not only do the files change. Other aspects may also change, such as:

* The algorithm (RSA, ECDSA, Ed25519… )
* The TLS protocol that supports it (1.2 vs 1.3)
* Compatible cipher suites

Therefore, **the nginx configuration must be adapted to the new certificate** so that it is effective and secure.

### What should be checked when using a different certificate?

1. **Key algorithm**
   * If you use a certificate **ECDSA**, you will need to keep specific suites enabled for `ECDHE-ECDSA`.
   * If you use a certificate **RSA**, nginx will use suites `ECDHE-RSA`, `DHE-RSA`, etc.
   * Some environments allow both certificates to be combined (`ssl_certificate` + `ssl_certificate_ecdsa`).
2. **TLS protocols**
   * Modern certificates (such as Let's Encrypt ECC ones) may require enabling **only TLS 1.2 and 1.3**.
   * Make sure that `ssl_protocols` is aligned with the certificate: `conf ssl_protocols TLSv1.2 TLSv1.3;`
3. **Cipher suites**
   * The directives `ssl_ciphers` must allow the algorithms supported by your certificate.
   * Check the corresponding section:
     * <https://nginx.org/en/docs/http/ngx\\_http\\_ssl\\_module.html#ssl\\_ciphers>
4. **Optional additional parameters**

   * If you use curve keys (ECDSA), consider reviewing or explicitly defining:

   ```conf
   ssl_ecdh_curve secp384r1;
   ```

   * You can add:

   ```conf
   ssl_certificate_key_file_type rsa;
   ```

   If nginx does not detect it correctly (version dependent).

***

### Documentation and testing

To properly adapt the configuration to your certificate, you can consult:

* [nginx: ssl\_certificate](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate)
* [ssl\_ciphers and support by certificate type](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_ciphers)
* [Mozilla SSL Config Generator](https://ssl-config.mozilla.org/)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/administradores/web.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
