> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v3.1/administradores/web.md).

# Servidor web

Editran Connect utiliza un servidor web integrado basado en **nginx**, instalado junto con la solución. Este componente sirve la interfaz web mediante HTTPS y actúa como proxy inverso hacia los servicios web internos del sistema.

***

## Ubicación del fichero de configuración

* Ruta del fichero: `<ruta_instalacion_connect>\server\nginx.conf`
* Ruta de los certificados:
  * Certificado: `<ruta_instalacion_connect>\server\certs\editran.pem`
  * Clave privada: `<ruta_instalacion_connect>\server\certs\editran.key`
* Raíz del contenido web: `<ruta_instalacion_connect>\EditranConnect\web`, webapp de connect.

### Puertos utilizados

| Puerto | Protocolo | Servicio expuesto                  |
| ------ | --------- | ---------------------------------- |
| 443    | HTTPS     | Interfaz web principal (nginx)     |
| 8081   | HTTP      | Backend funcional (`connect-back`) |
| 8085   | HTTP      | Servicio de firma (`editranff`)    |

### Rutas configuradas

| Ruta            | Tipo            | Destino interno                      |
| --------------- | --------------- | ------------------------------------ |
| `/`             | Estático        | `web/index.html`                     |
| `/connect-back` | Proxy inverso   | `http://localhost:8081/connect-back` |
| `/editranff`    | Proxy inverso   | `http://localhost:8085/editranff`    |
| `/50x.html`     | Página de error | `html/50x.html`                      |

### Seguridad TLS

| Parámetro              | Valor                                |
| ---------------------- | ------------------------------------ |
| Protocolos habilitados | TLSv1.2, TLSv1.3                     |
| Cifrados permitidos    | HIGH:!aNULL:!MD5                     |
| Preferencia de cifrado | Forzada por el servidor (on)         |
| Timeout de sesión SSL  | 5 minutos (`ssl_session_timeout 5m`) |

### Archivos importantes

| Archivo      | Descripción                                  |
| ------------ | -------------------------------------------- |
| `nginx.conf` | Configuración principal del servidor         |
| `index.html` | Página principal de la aplicación web        |
| `50x.html`   | Página mostrada ante errores 500/502/503/504 |

### Consideraciones administrativas

* El servidor escucha únicamente en el puerto 443 con SSL activado.
* Los servicios Java no están directamente expuestos, solo son accesibles a través de nginx.
* Cualquier modificación en `nginx.conf` requiere reiniciar nginx para aplicar los cambios.
* Es recomendable comprobar la validez de la configuración antes de reiniciar con el siguiente comando:

```bash
nginx.exe -t
```

> ⚠️ Importante: No modificar directamente nginx.conf sin hacer copia de seguridad. Asegurar la validez de los certificados instalados y la disponibilidad de los puertos configurados.

***

## Sustitución de certificados SSL en nginx

El servidor web de Editran Connect utiliza certificados locales instalados por defecto. Para entornos productivos, se recomienda sustituirlos por certificados más seguros propios, emitidos por una autoridad certificadora (CA) confiable o gestionados automáticamente mediante su herramienta de confianza al respecto.

> ⚠️ **Nota importante:**\
> Dado el amplio abanico de certificados SSL disponibles, sus variantes técnicas (RSA, ECDSA, ECC, Ed25519, etc.) y la rápida evolución de las recomendaciones de seguridad TLS, **este manual no cubre de forma detallada la configuración de todos los escenarios posibles**.
>
> Para obtener directrices actualizadas, se recomienda consultar directamente la [documentación oficial de nginx](https://nginx.org/en/docs/http/configuring_https_servers.html) y utilizar herramientas de referencia como el [Mozilla SSL Configuration Generator](https://ssl-config.mozilla.org/).
>
> Este apartado tiene como único propósito señalar los **ajustes clave que deben revisarse** al sustituir los certificados por otros distintos a los instalados por defecto.

### Consideración clave: el tipo de certificado afecta las directivas SSL

Al cambiar el certificado, no solo cambian los ficheros. También pueden cambiar aspectos como:

* El algoritmo (RSA, ECDSA, Ed25519…)
* El protocolo TLS que lo soporta (1.2 vs 1.3)
* Las suites de cifrado compatibles

Por eso, **la configuración de nginx debe adaptarse al nuevo certificado** para que sea efectivo y seguro.

### ¿Qué revisar al usar un certificado diferente?

1. **Algoritmo de clave**
   * Si usas un certificado **ECDSA**, necesitarás mantener habilitadas suites específicas para `ECDHE-ECDSA`.
   * Si usas un certificado **RSA**, nginx usará suites `ECDHE-RSA`, `DHE-RSA`, etc.
   * Algunos entornos permiten combinar ambos certificados (`ssl_certificate` + `ssl_certificate_ecdsa`).
2. **Protocolos TLS**
   * Certificados modernos (como los de Let's Encrypt ECC) pueden requerir habilitar **solo TLS 1.2 y 1.3**.
   * Asegúrate de que `ssl_protocols` esté alineado con el certificado: `conf ssl_protocols TLSv1.2 TLSv1.3;`
3. **Suites de cifrado**
   * Las directivas `ssl_ciphers` deben permitir los algoritmos compatibles con tu certificado.
   * Revisa el apartado correspondiente:
     * <https://nginx.org/en/docs/http/ngx\\_http\\_ssl\\_module.html#ssl\\_ciphers>
4. **Parámetros adicionales opcionales**

   * Si usas claves curvas (ECDSA), considera revisar o definir explícitamente:

   ```conf
   ssl_ecdh_curve secp384r1;
   ```

   * Puedes agregar:

   ```conf
   ssl_certificate_key_file_type rsa;
   ```

   Si nginx no lo detecta correctamente (versión dependiente).

***

### Documentación y pruebas

Para adaptar la configuración correctamente a tu certificado, puedes consultar:

* [nginx: ssl\_certificate](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate)
* [ssl\_ciphers y soporte por tipo de certificado](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_ciphers)
* [Mozilla SSL Config Generator](https://ssl-config.mozilla.org/)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v3.1/administradores/web.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
