--- title: "HTTP/HTTPS Server Module Documentation" description: "Documentation for HTTP/HTTPS Server" --- ## Table of Contents 1. [Navigation & Access](#navigation--access) 2. [Screenshots & Visual Interface](#screenshots--visual-interface) 3. [Module Overview (Technical)](#1-module-overview-technical) 4. [Module Overview (Commercial/Business)](#2-module-overview-commercialbusiness) 5. [Module Overview (End User/Administrator)](#3-module-overview-end-useradministrator) 6. [Configuration Sections](#4-configuration-sections) 7. [Settings Reference](#5-settings-reference) 8. [Common Scenarios & Examples](#6-common-scenarios--examples) 9. [Limitations & Important Notes](#7-limitations--important-notes) 10. [Troubleshooting Tips](#8-troubleshooting-tips) 11. [Glossary](#9-glossary) --- ## Navigation & Access To access the HTTP/HTTPS Server module: 1. Log in to the Ring2All Web Portal (`https:///login`). 2. In the left navigation sidebar, expand **Administration**. 3. Under **Network**, click **HTTP/HTTPS Server** (`/admin/system-settings/http-server`). 4. Configure HTTP/HTTPS listener ports, TLS protocols, cipher suites, HSTS, security headers, logging parameters, and default SSL certificate assignments. --- ## Screenshots & Visual Interface ### Web Engine & Reverse Proxy Parameters Comprehensive web server configuration console governing HTTP/HTTPS listener ports, minimum and maximum TLS protocol versions (TLS 1.2 and TLS 1.3), Modern cipher profiles, HSTS policy enforcement, rate limiting, and SSL/TLS certificate selection. ![HTTP/HTTPS Server Configuration](/screenshots/admin/network/http-server-form.png) --- ## 1. Module Overview (Technical) ### What Is the HTTP/HTTPS Server Module? HTTP/HTTPS Server is a **web server configuration module** that manages Nginx settings for the admin panel and API. It controls listeners, TLS policies, HSTS, logging, and rate limiting. ### Architecture ``` ┌─────────────────────────────────────────────────────────────────┐ │ HTTP/HTTPS Server Architecture │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ HTTP Server Configuration │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ Nginx Configuration │ │ │ │ │ │ │ │ Listeners: │ │ │ │ ├─ HTTP: 0.0.0.0:80 │ │ │ │ └─ HTTPS: 0.0.0.0:443 │ │ │ │ │ │ │ │ HTTPS Policy: │ │ │ │ ├─ TLS Min: 1.2 │ │ │ │ ├─ TLS Max: 1.3 │ │ │ │ ├─ Cipher: Modern │ │ │ │ └─ HSTS: Enabled (1 year) │ │ │ │ │ │ │ │ Security: │ │ │ │ ├─ Force HTTPS: ✓ │ │ │ │ ├─ Max Request: 10MB │ │ │ │ └─ Rate Limit: 100 req/10s │ │ │ │ │ │ │ │ Default Certificate: Production SSL │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ │ │ ▼ Applied to Nginx │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ Nginx Web Server │ │ │ │ │ │ │ │ Serves: │ │ │ │ ├─ Admin Panel (React App) │ │ │ │ ├─ API Endpoints │ │ │ │ ├─ Provisioning Files │ │ │ │ └─ Static Assets │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` --- ## 2. Module Overview (Commercial/Business) ### Business Value HTTP/HTTPS Server provides **secure web access**: | Without Configuration | With Configuration | |-----------------------|-------------------| | Default settings | Optimized security | | Basic TLS | Modern ciphers | | No HSTS | Browser enforcement | | No rate limits | Attack protection | ### Use Cases 1. **Security Hardening** - Enforce HTTPS only - Modern TLS settings 2. **Compliance** - PCI DSS requirements - TLS 1.2+ enforcement 3. **Performance** - Optimized settings - Rate limiting 4. **Flexibility** - Custom ports - Multi-interface binding ### Feature Highlights | Feature | Benefit | |---------|---------| | **Force HTTPS** | Secure all traffic | | **TLS Version Control** | Modern security | | **Cipher Profiles** | Easy configuration | | **HSTS** | Browser enforcement | | **Rate Limiting** | Attack protection | | **Access Logs** | Request tracking | --- ## 3. Module Overview (End User/Administrator) ### What Can You Do? - Configure HTTP/HTTPS ports - Enable/disable protocols - Force HTTPS redirect - Set TLS version limits - Choose cipher profile - Configure HSTS - Set default certificate - Enable rate limiting - Configure logging ### HTTP/HTTPS Server Interface ``` ┌─────────────────────────────────────────────────────────────────┐ │ HTTP/HTTPS Server │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Global listeners, TLS policies, and security settings │ │ │ │ [Reset to Defaults] │ │ │ │ ▼ Listeners │ │ Configure server ports and binding │ │ │ │ ┌─────────────────────────────────────────────────────────────┐│ │ │ ││ │ │ Enable HTTP: ✓ Enable HTTPS: ✓ ││ │ │ ││ │ │ HTTP Port: [80 ] HTTPS Port: [443 ] ││ │ │ ││ │ │ Bind Address: [0.0.0.0 ] ││ │ │ IP address to bind to (0.0.0.0 for all interfaces) ││ │ │ ││ │ └─────────────────────────────────────────────────────────────┘│ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ HTTPS Policy │ │ TLS settings and security policies │ │ │ │ ┌─────────────────────────────────────────────────────────────┐│ │ │ ││ │ │ Force HTTPS: ✓ ││ │ │ Redirect all HTTP traffic to HTTPS ││ │ │ ││ │ │ TLS Min Version: [TLS 1.2 ▼] TLS Max Version: [TLS 1.3 ▼]││ │ │ ││ │ │ Cipher Profile: [Modern (Most Secure) ▼] ││ │ │ Modern | Intermediate | Legacy ││ │ │ ││ │ │ ────────────────────────────────────────────────────────── ││ │ │ ││ │ │ HSTS Enabled: ✓ ││ │ │ ││ │ │ HSTS Max Age: [31536000 ] seconds (1 year) ││ │ │ ││ │ │ Include Subdomains: ✓ HSTS Preload: ☐ ││ │ │ ││ │ │ Disable TLS Renegotiation: ✓ ││ │ │ ││ │ └─────────────────────────────────────────────────────────────┘│ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Default Certificate │ │ Fallback certificate when no domain match is found │ │ │ │ ┌─────────────────────────────────────────────────────────────┐│ │ │ ││ │ │ Default TLS Certificate: [Production SSL ▼] ││ │ │ Used when accessing by IP or when domain is not ││ │ │ configured ││ │ │ ││ │ └─────────────────────────────────────────────────────────────┘│ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ▼ Logging & Security │ │ Access logging and security settings │ │ │ │ ┌─────────────────────────────────────────────────────────────┐│ │ │ ││ │ │ Access Log: ✓ Error Log Level: [warn ▼] ││ │ │ ││ │ │ Max Request Size: [10485760 ] bytes (10MB) ││ │ │ ││ │ │ ────────────────────────────────────────────────────────── ││ │ │ ││ │ │ Rate Limiting: ✓ ││ │ │ ││ │ │ Max Requests: [100 ] Time Window: [10 ] sec ││ │ │ ││ │ └─────────────────────────────────────────────────────────────┘│ │ │ │ [Save Configuration] │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Quick Tips > [!TIP] > **Force HTTPS**: Always enable for production. > [!TIP] > **Modern Ciphers**: Best security for current browsers. > [!WARNING] > **HSTS Preload**: Irreversible - test thoroughly first. --- ## 4. Configuration Sections ### Listeners | Field | Description | |-------|-------------| | **Enable HTTP** | Allow HTTP connections | | **Enable HTTPS** | Allow HTTPS connections | | **HTTP Port** | HTTP port (default 80) | | **HTTPS Port** | HTTPS port (default 443) | | **Bind Address** | Interface to bind | ### HTTPS Policy | Field | Description | |-------|-------------| | **Force HTTPS** | Redirect HTTP to HTTPS | | **TLS Min Version** | Minimum TLS (1.2 recommended) | | **TLS Max Version** | Maximum TLS (1.3) | | **Cipher Profile** | Cipher suite selection | | **HSTS Enabled** | Strict Transport Security | | **HSTS Max Age** | HSTS duration (seconds) | | **Include Subdomains** | Apply to subdomains | | **HSTS Preload** | Browser preload list | | **Disable TLS Renegotiation** | Prevent attacks | ### Default Certificate | Field | Description | |-------|-------------| | **Default TLS Certificate** | Fallback certificate | ### Logging & Security | Field | Description | |-------|-------------| | **Access Log** | Log all requests | | **Error Log Level** | Minimum log severity | | **Max Request Size** | Body size limit | | **Rate Limiting** | Enable rate limits | | **Max Requests** | Requests per window | | **Time Window** | Rate limit window | --- ## 5. Settings Reference ### TLS Versions | Version | Status | Recommendation | |---------|--------|----------------| | TLS 1.0 | Deprecated | ❌ Don't use | | TLS 1.1 | Deprecated | ❌ Don't use | | TLS 1.2 | Current | ✓ Minimum | | TLS 1.3 | Modern | ✓ Preferred | ### Cipher Profiles | Profile | Security | Compatibility | |---------|----------|---------------| | **Modern** | Highest | Current browsers | | **Intermediate** | High | Older browsers | | **Legacy** | Medium | Very old clients | ### HSTS Max Age Values | Duration | Seconds | Use | |----------|---------|-----| | 1 day | 86400 | Testing | | 1 week | 604800 | Initial | | 1 month | 2592000 | Transitional | | 1 year | 31536000 | Production | | 2 years | 63072000 | Long-term | ### Error Log Levels | Level | Description | |-------|-------------| | **debug** | Very verbose | | **info** | Informational | | **warn** | Warnings (recommended) | | **error** | Errors only | | **crit** | Critical only | --- ## 6. Common Scenarios & Examples ### Scenario 1: Secure Production Setup 1. Enable HTTP and HTTPS 2. Force HTTPS = ✓ 3. TLS Min = 1.2, Max = 1.3 4. Cipher = Modern 5. HSTS Enabled, Max Age = 1 year 6. Include Subdomains = ✓ 7. Select default certificate 8. Save ### Scenario 2: Development Setup 1. Enable HTTP and HTTPS 2. Force HTTPS = ☐ 3. TLS Min = 1.2 4. Cipher = Intermediate 5. HSTS = ☐ (disabled) 6. Save ### Scenario 3: Enable Rate Limiting 1. Rate Limiting = ✓ 2. Max Requests = 100 3. Time Window = 10 seconds 4. Save 5. (100 requests per 10 seconds per IP) ### Scenario 4: Change Ports 1. HTTP Port = 8080 2. HTTPS Port = 8443 3. Bind Address = 0.0.0.0 4. Save 5. Restart Nginx --- ## 7. Limitations & Important Notes ### Technical Notes > [!NOTE] > **Port Changes**: May require service restart. > [!NOTE] > **Bind Address**: 0.0.0.0 = all IPv4, :: = all IPv6. > [!WARNING] > **HSTS Preload**: Permanent inclusion - test first! ### Best Practices 1. **Always Force HTTPS**: Security baseline 2. **TLS 1.2 Minimum**: Industry standard 3. **Modern Ciphers**: When possible 4. **Enable HSTS**: After HTTPS stable 5. **Rate Limiting**: Protect against abuse ### Security Recommendations | Setting | Production Value | |---------|------------------| | Force HTTPS | ✓ Enabled | | TLS Min | 1.2 | | Cipher Profile | Modern | | HSTS | ✓ Enabled, 1 year | | TLS Renegotiation | ✓ Disabled | | Rate Limiting | ✓ Enabled | --- ## 8. Troubleshooting Tips ### Common Issues | Symptom | Possible Cause | Solution | |---------|---------------|----------| | Can't connect | Wrong port | Check ports | | SSL error | No certificate | Set default cert | | HSTS issue | Preload stuck | Wait or use different domain | | Rate limited | Too many requests | Adjust limits | ### Test Configuration ```bash # Test Nginx config nginx -t # Check listening ports ss -tlnp | grep nginx # Test TLS version openssl s_client -connect localhost:443 -tls1_2 # Check HTTPS headers curl -I https://localhost ``` ### Check Nginx Status ```bash # Service status systemctl status nginx # Reload config systemctl reload nginx # View access log tail -f /var/log/nginx/access.log # View error log tail -f /var/log/nginx/error.log ``` --- ## 9. Glossary | Term | Definition | |------|------------| | **TLS** | Transport Layer Security | | **HSTS** | HTTP Strict Transport Security | | **Cipher** | Encryption algorithm | | **Rate Limiting** | Request throttling | | **Preload** | Browser built-in HSTS | | **Bind Address** | Interface IP | --- *Documentation last updated: January 2026*