Setting up an mSign server: Difference between revisions

From Scriptel Wiki
Jump to navigation Jump to search
(Created page with "This guide is for administrators in organizations who have purchased an mSign server license. Scriptel provides a public server for public use free of charge at msign.scriptel...")
 
No edit summary
 
(32 intermediate revisions by 2 users not shown)
Line 1: Line 1:
This guide is for administrators in organizations who have purchased an mSign server license. Scriptel provides a public server for public use free of charge at msign.scriptel.com. However, this requires internet connectivity and is shared. Organizations may wish to use their own server behind their firewall.
This guide is for administrators in organizations who have purchased an mSign server license. Scriptel provides a public server for public use free of charge at msign.scriptel.com. However, this requires internet connectivity and is shared. Organizations may wish to use their own server behind their firewall. A 90-day trial license is available upon request.  


mSign Sever is designed to run on an Ubuntu 16.04 server. It is written node.js, so technically it is possible to make it run on any platform that supports node. However, all of the scripts for installing are written for Ubuntu and that is all we are currently supporting.
mSign Sever is designed to run on an Ubuntu 20.04 server and up. It is written node.js, so technically it is possible to make it run on any platform that supports node. However, all of the scripts for installing are written for Ubuntu and that is all we are currently supporting.


mSign Server requires connection to a PostgreSQL database. This can live on the local machine or elsewhere. These instructions will assume it lives on the local system.
===Set up the service:===


===Steps:===
1. Obtain the scriptel-msign-x.x.xx-all.deb package.


1. Obtain the scriptel-msign-x.x.xx-all.deb package and license file from Scriptel
2. Obtain a server with Ubuntu 20.04 (or higher) on it.


2. Place the package in /var/cache/apt/archives<br />
3. Change the host name
    sudo mv scriptel-msign-*-all.deb /var/cache/apt/archives<br />
     sudo hostnamectl set-hostname new-hostname
    sudo chmod root:root scriptel-msign-*-all.deb
3. Install PostgreSQL
     sudo apt-get install postgresql postgresql-contrib


4. Configure PostgreSQL for TCP login by editing /etc/postgresql/X.X/main/pg_hba.conf
4. Point your DNS to the new server.


5. Find the line that says
5. Start the install of mSign server
     host    all            all            127.0.0.1/32            peer
     sudo dpkg -i scriptel-msign-X.X.X-all.deb


6. Replace 'peer' with 'md5'. Save and exit the file.
6. Edit the /usr/lib/scriptel-msign/config.js file.
# hostName must be set to the fully qualified domain name for SSL to work.
# webappLocation must be set to the URL of the front-end server.
# publicHttpsPort is the port that the front end should connect to. Change this to 443.
# Everything else should work by default.


7. Restart PostgreSQL
7. Restart the service to pick up the changes by stopping and starting it. restart does not work.
    sudo service PostgreSQL restart
  sudo service scriptel-msign stop
  sudo service scriptel-msign start


8. Start commandline PostgreSQL
8. check to see if the service is started the service
     sudo -u postgres psql
     sudo service scriptel-msign status


9. type
At this point, your mSign Desktop and mSign Mobile applications should be able to connect to the server on port 8443. For example, if your IP address were 54.291.191.59 you would put this into the applications as https://54.291.191.59:8443. You can try this using a browser for mSign Mobile as long as it will allow you to get to it as an unsafe site. Chrome will allow this, for example, but you will not be able to use the mSign mobile app for Android until there is an SSL certificate.
    CREATE USER 'scriptel-msign' WITH PASSWORD 'secret';
    CREATE DATABASE 'scriptel-msign' WITH OWNER 'scriptel-msign';
    \q


10. Start the install of mSign server
===Reassign the ports===
    sudo apt-get install -f scriptel-msign-1.0.37-all.deb


11. Create the schema
This section is optional. mSign Server runs natively on ports 8080 and 8443. You might want to use the standard http and https ports 80 and 443. You have to do this if you use Letsencrypt for a certificate in the next section.
    sudo -u scriptel-msign node /usr/lib/scriptel-msign/msign-util.js -i


12. Create the user
Note that eth0 may or may not be the name of your ethernet adaptor. For example, on AWS T4g instances it is ens5.
    sudo node /usr/lib/scriptel-msign/msign-util.js --create-user=guy@email.com:guysPassword


13. Create an organization
  sudo apt install iptables-persistent
    sudo node /usr/lib/scriptel-msign/msign-util.js -o organization
  sudo iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 8080
  sudo iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 443 -j REDIRECT --to-port 8443
  sudo /etc/init.d/netfilter-persistent save


14. Assign the user to the organization
===Certificate types===
     sudo node /usr/lib/scriptel-msign/msign-util.js -a guy@email.com:organization
 
There are two certificates. One is for SSL between the server and the browser and the server and the desktop. The other is for the mobile application (front end).
 
===SSL Key===
 
To avoid security warnings you need to install a certificate. You can buy one and install it. Or you can self-certify, but if you do, you will have to set yourself up as a root authority on each mobile device you use. Or you can use [https://letsencrypt.org/ Let's Encrypt], which is free, but requires that the server be public on the internet so that it can validate ownership of the domain.
 
These instructions are for Let's Encrypt:
 
1. Let's Encrypt requires that standard ports be used. So if you haven't already done so, reassign the ports as described in the previous section.
 
2. Give your server a DNS name with your DNS provider and wait for it to propogate. This can be a subdomain of one you already own.
 
3. Create the directory /usr/lib/scriptel-msign/www and change the owner to scriptel-msign
  sudo mkdir /usr/lib/scriptel-msign/www
  sudo chown scriptel-msign /usr/lib/scriptel-msign/www
 
4. Type the following, substituting your domain for domain.example.com:
    sudo apt install certbot
     sudo certbot certonly --webroot -w /usr/lib/scriptel-msign/www -d domain.example.com
 
===Mobile certificate===
 
This is the certficate pointed to in config.js. When the installer is run, a self-signed certificate is generated but it does not chain up to a root authority. In order to avoid security warnings on the mobile device, a certficate for the front end server's domain must be obtained. This can be done through Amazon's certificate manager, for example.

Latest revision as of 14:58, 29 June 2023

This guide is for administrators in organizations who have purchased an mSign server license. Scriptel provides a public server for public use free of charge at msign.scriptel.com. However, this requires internet connectivity and is shared. Organizations may wish to use their own server behind their firewall. A 90-day trial license is available upon request.

mSign Sever is designed to run on an Ubuntu 20.04 server and up. It is written node.js, so technically it is possible to make it run on any platform that supports node. However, all of the scripts for installing are written for Ubuntu and that is all we are currently supporting.

Set up the service:

1. Obtain the scriptel-msign-x.x.xx-all.deb package.

2. Obtain a server with Ubuntu 20.04 (or higher) on it.

3. Change the host name

   sudo hostnamectl set-hostname new-hostname

4. Point your DNS to the new server.

5. Start the install of mSign server

   sudo dpkg -i scriptel-msign-X.X.X-all.deb

6. Edit the /usr/lib/scriptel-msign/config.js file.

  1. hostName must be set to the fully qualified domain name for SSL to work.
  2. webappLocation must be set to the URL of the front-end server.
  3. publicHttpsPort is the port that the front end should connect to. Change this to 443.
  4. Everything else should work by default.

7. Restart the service to pick up the changes by stopping and starting it. restart does not work.

  sudo service scriptel-msign stop
  sudo service scriptel-msign start

8. check to see if the service is started the service

   sudo service scriptel-msign status

At this point, your mSign Desktop and mSign Mobile applications should be able to connect to the server on port 8443. For example, if your IP address were 54.291.191.59 you would put this into the applications as https://54.291.191.59:8443. You can try this using a browser for mSign Mobile as long as it will allow you to get to it as an unsafe site. Chrome will allow this, for example, but you will not be able to use the mSign mobile app for Android until there is an SSL certificate.

Reassign the ports

This section is optional. mSign Server runs natively on ports 8080 and 8443. You might want to use the standard http and https ports 80 and 443. You have to do this if you use Letsencrypt for a certificate in the next section.

Note that eth0 may or may not be the name of your ethernet adaptor. For example, on AWS T4g instances it is ens5.

 sudo apt install iptables-persistent
 sudo iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 8080
 sudo iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 443 -j REDIRECT --to-port 8443
 sudo /etc/init.d/netfilter-persistent save

Certificate types

There are two certificates. One is for SSL between the server and the browser and the server and the desktop. The other is for the mobile application (front end).

SSL Key

To avoid security warnings you need to install a certificate. You can buy one and install it. Or you can self-certify, but if you do, you will have to set yourself up as a root authority on each mobile device you use. Or you can use Let's Encrypt, which is free, but requires that the server be public on the internet so that it can validate ownership of the domain.

These instructions are for Let's Encrypt:

1. Let's Encrypt requires that standard ports be used. So if you haven't already done so, reassign the ports as described in the previous section.

2. Give your server a DNS name with your DNS provider and wait for it to propogate. This can be a subdomain of one you already own.

3. Create the directory /usr/lib/scriptel-msign/www and change the owner to scriptel-msign

  sudo mkdir /usr/lib/scriptel-msign/www
  sudo chown scriptel-msign /usr/lib/scriptel-msign/www

4. Type the following, substituting your domain for domain.example.com:

   sudo apt install certbot
   sudo certbot certonly --webroot -w /usr/lib/scriptel-msign/www -d domain.example.com

Mobile certificate

This is the certficate pointed to in config.js. When the installer is run, a self-signed certificate is generated but it does not chain up to a root authority. In order to avoid security warnings on the mobile device, a certficate for the front end server's domain must be obtained. This can be done through Amazon's certificate manager, for example.