Setup the Webserver for the FAST Website #51

Closed
opened 2023-11-02 10:22:36 +00:00 by inf3527 · 19 comments
inf3527 commented 2023-11-02 10:22:36 +00:00 (Migrated from gitlab.rlp.net)

As a User I need a Website to use the FAST Webapp in a Browser.

  • Webserver-Software chosen (prod.)
  • Webserver installed on the Server
  • Webserver is connected to the Pipeline -> Main Branch
  • Webserver is active and able to host the working, production-ready version of the Webapp (main-branch)
  • Website has a working SSL-Certificate

AC: Website hosts the current prod. version of the FAST-Webapp over a HTTPS-Connection

As a User I need a Website to use the FAST Webapp in a Browser. * [x] Webserver-Software chosen (prod.) * [x] Webserver installed on the Server * [x] Webserver is connected to the Pipeline -\> Main Branch * [x] Webserver is active and able to host the working, production-ready version of the Webapp (main-branch) * [x] Website has a working SSL-Certificate AC: Website hosts the current prod. version of the FAST-Webapp over a HTTPS-Connection
inf3527 commented 2023-11-09 13:30:02 +00:00 (Migrated from gitlab.rlp.net)

changed the description

changed the description
inf3527 commented 2023-11-14 09:38:56 +00:00 (Migrated from gitlab.rlp.net)

marked the checklist item Webserver-Software chosen (prod.) as completed

marked the checklist item **Webserver-Software chosen (prod.)** as completed
inf3527 commented 2023-11-14 09:38:58 +00:00 (Migrated from gitlab.rlp.net)

marked the checklist item Webserver installed on the Server as completed

marked the checklist item **Webserver installed on the Server** as completed
inf3527 commented 2023-11-14 09:39:16 +00:00 (Migrated from gitlab.rlp.net)

assigned to @inf3447 and @inf3479

assigned to @inf3447 and @inf3479
inf3479 commented 2023-11-16 09:05:44 +00:00 (Migrated from gitlab.rlp.net)

changed health status to at risk

changed health status to **at risk**
inf3479 commented 2023-11-16 09:07:09 +00:00 (Migrated from gitlab.rlp.net)

ssh connection to pse-w23.projekte.it.hs-worms.de is only possible from HS-Network.

POSSIBLE FIX: To deploy we would have to vpn into the HS-Network or open the server to other networks.

ssh connection to `pse-w23.projekte.it.hs-worms.de` is only possible from HS-Network. POSSIBLE FIX: To deploy we would have to vpn into the HS-Network or open the server to other networks.
inf3479 commented 2023-11-16 09:07:22 +00:00 (Migrated from gitlab.rlp.net)

assigned to @inf3527

assigned to @inf3527
inf3527 commented 2023-11-21 09:05:55 +00:00 (Migrated from gitlab.rlp.net)

grafik.png

For the Firewall Rule, we need the following details. It is possible, but we need to create a new request.

![grafik.png](/uploads/f47417e0aefa50641232c667ccc24ace/grafik.png) For the Firewall Rule, we need the following details. It is possible, but we need to create a new request.
inf3527 commented 2023-11-21 10:17:06 +00:00 (Migrated from gitlab.rlp.net)

Protocol: TCP

Source-IPs: 134.93.175.221 - 134.93.175.223

Target-IP: 143.93.191.157

Target-Port: 22

Protocol: TCP Source-IPs: 134.93.175.221 - 134.93.175.223 Target-IP: 143.93.191.157 Target-Port: 22
inf3479 commented 2023-11-21 15:46:21 +00:00 (Migrated from gitlab.rlp.net)

changed health status to on track

changed health status to **on track**
inf3479 commented 2023-11-21 15:46:23 +00:00 (Migrated from gitlab.rlp.net)

removed health status on track

removed health status **on track**
inf3527 commented 2023-11-23 12:13:29 +00:00 (Migrated from gitlab.rlp.net)

marked the checklist item Webserver is connected to the Pipeline -> Main Branch as completed

marked the checklist item **Webserver is connected to the Pipeline -\> Main Branch** as completed
inf3447 commented 2023-11-23 13:22:30 +00:00 (Migrated from gitlab.rlp.net)

unassigned @inf3479, @inf3527, and @inf3447

unassigned @inf3479, @inf3527, and @inf3447
inf3321 commented 2023-11-23 14:35:47 +00:00 (Migrated from gitlab.rlp.net)

assigned to @inf3479

assigned to @inf3479
inf3479 commented 2023-11-23 17:41:08 +00:00 (Migrated from gitlab.rlp.net)

config passt soweit nur:

Von nginx bekomme ich ein key mismatch dev@pse-w23:/etc/nginx/sites-enabled$ sudo nginx -t 2023/11/23 18:36:31 [emerg] 85593#85593: SSL_CTX_use_PrivateKey("/etc/ssl/signing-request-priv-key.pem") failed (SSL: error:05800074:x509 certificate routines::key values mismatch) nginx: configuration file /etc/nginx/nginx.conf test failed

und die keys selbst passen dann auch nicht dev@pse-w23:/etc/nginx/sites-enabled$ sudo openssl rsa -modulus -noout -in /etc/ssl/signing-request-priv-key.pem Modulus=C7F2BD279E485BEBB68848C4BE7D2CB1067217B5FE959F0DFE729534BF90C09C2AFE482F343D923F8473F5A82AAA9F765FF8CC0F05926950CADD8B8B7C80DB1D19CC3BC8FE8FEFC47500DB11CF8B2031342E05D641E716833ED4956AC08425BE601EE4ECD32848E4E37418B4066A8E9EC8AE4CA9C7F853F65596ABD3BE9EDF9B5CA886E41D1E24BBC9AAA2A084E7A5EB03CA87C52B43FBFCC503204DC47E63D486E61692E7B2A75D0B28273582F4B826FBAED3E556B47A556155D990E18A7DB64941252B1DE033531A924069120F50FA066C0EDD94302161664E6707AF48D7838CC17C1084200B4943A4A9B46C434DABD873E1A81963108F6A728F2E4D3C85D1 dev@pse-w23:/etc/nginx/sites-enabled$ openssl x509 -modulus -noout -in /etc/ssl/pse-w23_projekte_it_hs-worms_de.cer Modulus=BE409DF46EE1EA76871C4D45448EBE46C883069DC12AFE181F8EE402FAF3AB5D508A16310B9A06D0C57022CD492D5463CCB66E68460B53EACB4C24C0BC724EEAF115AEF4549A120AC37AB23360E2DA8955F32258F3DEDCCFEF8386A28C944F9F68F29890468427C776BFE3CC352C8B5E07646582C048B0A891F9619F762050A891C766B5EB78620356F08A1A13EA31A31EA099FD38F6F62732586F07F56BB8FB142BAFB7AACCD6635F738CDA0599A838A8CB17783651ACE99EF4783A8DCF0FD942E2980CAB2F9F0E01DEEF9F9949F12DDFAC744D1B98B547C5E529D1F99018C7629CBE83C7267B3E8A25C7C0DD9DE6356810209D8FD8DED2C3849C0D5EE82FC9

config passt soweit nur: Von nginx bekomme ich ein key mismatch `dev@pse-w23:/etc/nginx/sites-enabled$ sudo nginx -t 2023/11/23 18:36:31 [emerg] 85593#85593: SSL_CTX_use_PrivateKey("/etc/ssl/signing-request-priv-key.pem") failed (SSL: error:05800074:x509 certificate routines::key values mismatch) nginx: configuration file /etc/nginx/nginx.conf test failed` und die keys selbst passen dann auch nicht `dev@pse-w23:/etc/nginx/sites-enabled$ sudo openssl rsa -modulus -noout -in /etc/ssl/signing-request-priv-key.pem Modulus=C7F2BD279E485BEBB68848C4BE7D2CB1067217B5FE959F0DFE729534BF90C09C2AFE482F343D923F8473F5A82AAA9F765FF8CC0F05926950CADD8B8B7C80DB1D19CC3BC8FE8FEFC47500DB11CF8B2031342E05D641E716833ED4956AC08425BE601EE4ECD32848E4E37418B4066A8E9EC8AE4CA9C7F853F65596ABD3BE9EDF9B5CA886E41D1E24BBC9AAA2A084E7A5EB03CA87C52B43FBFCC503204DC47E63D486E61692E7B2A75D0B28273582F4B826FBAED3E556B47A556155D990E18A7DB64941252B1DE033531A924069120F50FA066C0EDD94302161664E6707AF48D7838CC17C1084200B4943A4A9B46C434DABD873E1A81963108F6A728F2E4D3C85D1 dev@pse-w23:/etc/nginx/sites-enabled$ openssl x509 -modulus -noout -in /etc/ssl/pse-w23_projekte_it_hs-worms_de.cer Modulus=BE409DF46EE1EA76871C4D45448EBE46C883069DC12AFE181F8EE402FAF3AB5D508A16310B9A06D0C57022CD492D5463CCB66E68460B53EACB4C24C0BC724EEAF115AEF4549A120AC37AB23360E2DA8955F32258F3DEDCCFEF8386A28C944F9F68F29890468427C776BFE3CC352C8B5E07646582C048B0A891F9619F762050A891C766B5EB78620356F08A1A13EA31A31EA099FD38F6F62732586F07F56BB8FB142BAFB7AACCD6635F738CDA0599A838A8CB17783651ACE99EF4783A8DCF0FD942E2980CAB2F9F0E01DEEF9F9949F12DDFAC744D1B98B547C5E529D1F99018C7629CBE83C7267B3E8A25C7C0DD9DE6356810209D8FD8DED2C3849C0D5EE82FC9`
inf3527 commented 2023-11-30 09:57:28 +00:00 (Migrated from gitlab.rlp.net)

Neues Zertifikat angefordert, das bisherige war fehlerhaft.

grafik.png

Neues Zertifikat angefordert, das bisherige war fehlerhaft. ![grafik.png](/uploads/f69bc36869d2dc6b9299be89e30226a5/grafik.png)
inf3527 commented 2023-11-30 09:59:07 +00:00 (Migrated from gitlab.rlp.net)

marked the checklist item Webserver is active and able to host the working, production-ready version of the Webapp (main-branch) as completed

marked the checklist item **Webserver is active and able to host the working, production-ready version of the Webapp (main-branch)** as completed
inf3527 commented 2023-11-30 09:59:08 +00:00 (Migrated from gitlab.rlp.net)

marked the checklist item Website has a working SSL-Certificate as completed

marked the checklist item **Website has a working SSL-Certificate** as completed
inf3527 commented 2023-11-30 09:59:45 +00:00 (Migrated from gitlab.rlp.net)

assigned to @inf3527

assigned to @inf3527
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
lukasdohn/fast#51
No description provided.