This document provides information on how to configure the Nginx publishing profile to make it possible to install and publish certificates on the server.
Requirements
- A device registered in the Segura® Platform with Nginx installed and configured. More information in How to configure a device.
- The credential used to connect to the Nginx server must belong to the
sudoersgroup on the target server. Publishing a certificate always runs the privileged commands withsudo.AttentionIf the credential uses an SSH key instead of a password, the configured user must also have the
NOPASSWDpermission enabled in the server'ssudoersfile. Without it, publishing fails. - If you are publishing a certificate with a password, you must create a file with the password and declare it in the configuration file through the Nginx
ssl_password_fileparameter. More information in Module ngx_http_ssl_module.
Configure Nginx
To configure Nginx, see the following steps:
- On Segura® Platform, in the navigation bar, hover over the Products menu and select Certificate Manager.
- From the side menu, go to Publishing > Publishing profiles.
- Click the Add button and select Nginx.
- In the Settings tab, complete the following fields:
- In the Profile name * field, enter the profile's name.
- In the Credential username field, enter the name of the credential used to access the Nginx server.
- Optional: Check the Use a registered credential to access all devices option, and in the Access credential registered in the system field, select the access credential registered in Segura® Platform to be used to access the Nginx server.
- Click Continue.
- In the Nginx tab, complete the following fields:
- Optional: In the Site field, enter the site where the certificate will be published. If the site is unavailable or no value is entered, Nginx publishes the certificate to its default site.
- In the Configuration file path field, enter the configuration file path in the Nginx server. For example:
etc/nginx/sites-available/example.conf. - In the Port field, enter the port used in this site. The default port is 443.
- In the Delete password file after publication (if the file exists) field, select Yes to delete the password file after the certificate is published.
- Click Continue.
- In the Devices tab, select the device where Nginx is installed.
- In the Review tab, review all the information entered previously and click Save.
After configuring Nginx, the profile appears in the Publishing profiles report. Now, you can publish certificates in your Nginx server. More information in How to publish a certificate.