Showing posts with label NGINX. Show all posts
Showing posts with label NGINX. Show all posts

Saturday, July 9, 2022

How to Restrict Request Method in NGINX


HTTP and HTTPS protocol has several request methods. POST, GET, PUT, PATCH, HEAD and DELETE. When we configuraing NGINX web server we need to restrict PUT,PATCH and DELETE request methods. Only POST, GET and HEAD methods enough to enable from web sever.

Configurations

For Static Content

location /request {
        if ( $request_method !~ ^(GET|POST|HEAD)$ )
        {
                return 405;
        }
        root  /usr/share/nginx/html;
}

For Proxy Pass

location /request-Proxy {
        if ( $request_method !~ ^(GET|POST|HEAD)$ )
        {
                return 405;
        }
        proxy_pass      https://127.0.0.1:8380;
}

Output

GET Request 




DELETE Request






How to configure Go-access Real-time HTML Outputs (NGINX)

 

How to configure Go-access Real-time HTML Outputs

Requirement

Configure Go-Access for NGINX real-time access logs.

GoAccess has the ability the output real-time data in the HTML report. You can even email the HTML file since it is composed of a single file with no external file dependencies, how neat is that!

The process of generating a real-time HTML report is very similar to the process of creating a static report. Only --real-time-html is needed to make it real-time.

Pre-Requisites 

  • NGINX web server which support websocket
  • Install goaccess on the same server

Step 01: Configure NGINX proxy pass for goaccess real-time push

Add below proxy pass to relevant NGINX configuration.

location /ws-goaccess {
        proxy_pass  http://127.0.0.1:9870;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
}

In my case Go-Access websocket port listen locally with port 9870.

Step 02: Identify log format of your NGINX web server

I used this GitHum repository to find out log format for goaccess.

URL: https://github.com/stockrt/nginx2goaccess 

Command Usage

Usage: ./nginx2goaccess.sh '<log_format>'

NGINX log format u have to get from your web server. It should be in nginx.conf file. Configuration parameter "log_format"

Step 03: Start the Go-Access WebSocket Server

goaccess /var/log/nginx/data.vidutech.org-access.log /var/log/nginx/www.vidutech.org-access.log --log-format='%h - %^ [%d:%t %^] "%r" "%b" "%R" "%u" "%^"' --date-format=%d/%b/%Y --time-format=%T -o /usr/share/nginx/html/goaccess.html --real-time-html --addr=127.0.0.1 --port=9870 --ws-url=data.vidutech.org/ws-goaccess

Command Explanation

We can pass several log files as input

  • /var/log/nginx/data.vidutech.org-access.log
  • /var/log/nginx/www.vidutech.org-access.log
--log-format  / --date-format / --time-format
  • You can obtain it from Step 02
-o <output File>
  • Go-Access report should be save under nginx share location.  This file should be accessible via browser with server name.
--real-time-html

  • Start server as real-time 
--addr=127.0.0.1 --port=9870
  • Listen address and port
--ws-url
  • Web Socket URL.


Once you start the Go-Access server use web socket client to check whether web-socket is working. Here I am using Google Chrome extension "Simple Web Socket Client"








If Web-Socket is working it will display Open.






How you can access the Go-Access html report from your browser. In my case URL for report is 

URL: https://data.vidutech.org/goaccess.html





Friday, June 24, 2022

Benchmark Your NGINX WEB Server

 

Benchmark Your NGINX WEB Server

There are lots of commercial and open source tools to benchmark your web server. In this blog I and going to demonstrate benchmark your web server with CIS benchmark policies. Any one can freely download CIS documents.

CIS Download URL:  https://www.cisecurity.org/benchmark/nginx

"The CIS Benchmarks are distributed free of charge in PDF format to propagate their worldwide use and adoption as user-originated, de facto standards. CIS Benchmarks are the only consensus-based, best-practice security configuration guides both developed and accepted by government, business, industry, and academia."

Download benchmark scrip: https://github.com/viduranga0006/nginx-benchmark

This is a bash shell script. You have to run it with supper user. Once you execute, you have to select relevant category. At the end it will list summary of benchmark results.





Sunday, November 7, 2021

How to Generate Self-Signed Certificate with your own CA

 

How to Generate Self-Signed Certificate with your own CA

In this blog I am going to demonstrate how to generate a self-sign certificate for your local domain for testing purpose.

Prerequisites 

You need to have a LINUX PC or a server to do this, because this script is wrote in bash. Other than that u have to install openssl package to generate certificate.

Download the self-sign certificate from GITHUB from this Link. Download.

Step:1: Extract the content

tar -xvzf selfsign-cert.tar.gz










Step: 2: Generate CA Certificate

./start
  • Select "Genarate New CA Certificate" option
  • Enter CA Name without space. 

























Step: 3: Generate Host Certificate

./start
  • Select "Genarate New Host Certificate" Option
  • Enter Host Certificate name.
  • Enter Domain list. If you are going to use it for multiple site, you have to mention each hostnames.



























Step: 4: Sign Host Certificate

./start
  • Select "Sign Host certificate" Option
  • Enter Host Certificate you want to sign.
  • Enter CA to sign with.



























Sign Certificate and Private Key are locate in below path.

Signed Certificate Path.......: cert/server/sign/test.vidutech.org.pem
Private Key Path.................: cert/server/key/test.vidutech.org.key

You can use these sign certificate and private key to put in Apache or NGINX.

By installing CA certificate in browser, you can avoid CA certificate warning in browser.   

Thursday, November 5, 2020

NGINX with Letsencrypt

 

NGINX with Letsencrypt


Let's Encrypt is a non-profit certificate authority run by Internet Security Research Group (ISRG) that provides X.509 certificates for Transport Layer Security (TLS) encryption at no charge. It launched on April 12, 2016.


Let's Encrypt certificates are valid for 90 days, during which renewal can take place at any time. The offer is accompanied by an automated process designed to overcome manual creation, validation, signing, installation, and renewal of certificates for secure websites. The project claims its goal is to make encrypted connections to World Wide Web servers ubiquitous.[6] By eliminating payment, web server configuration, validation email management and certificate renewal tasks, it is meant to significantly lower the complexity of setting up and maintaining TLS encryption.[1]

[1] Wikipedia

Prerequisite

  • Linux server with nginx installed (Port 80 and 443 should open for public)
  • There should be a DNS entry for your site.
  • "git" "wget" packages should install in your server.

In this example I am using CentOS 8

Step 01: Install Prerequisite

Install git and wget

yum install git wget


Step 02: Install NGINX

Download the nginx RPM from nginx official site base on your operation system and install.

NGINX Official Site: https://nginx.org/packages/


Install the nginx RPM

rpm -ivh nginx-1.18.0-2.el8.ngx.x86_64.rpm


Enable the nginx service and start

systemctl enable nginx
systemctl start nginx



Now try to access your site using host name. 

Step 03: Install letsencrypt

Clone the "letsencrypt" from GitHub

git clone https://github.com/letsencrypt/letsencrypt


Go inside the letsencrypt folder and execute this command.

./letsencrypt-auto certonly --webroot --webroot-path /usr/share/nginx/html/ --email <your-email-address> -d <your-site-name>


This will take some time to do the installation. 
Finally you will get a output like this.


Step 04: Configure NGINX for HTTPS

Got to nginx configuration folder "/etc/nginx/conf.d"



Create a new .conf file and add below content.

server {
    listen 443 ssl;
    server_name <Your-Site-Name>;

    ssl_certificate             /etc/letsencrypt/live/<Your-Site-Name>/fullchain.pem;
    ssl_certificate_key         /etc/letsencrypt/live/<Your-Site-Name>/privkey.pem;

    ssl_session_cache shared:SSL:10m;
    ssl_session_timeout  5m;

    ssl_protocols   TLSv1.2;
    ssl_ciphers  ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!eNULL:!MD5:!DSS;
    ssl_prefer_server_ciphers   on;

    # HSTS
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;

    access_log /var/log/nginx/<Your-Site-Name>-access main;
    error_log  /var/log/nginx/<Your-Site-Name>-error warn;

    location / {
        root /usr/share/nginx/html;
    }

    location /.well-known/acme-challenge/ {
        root   /usr/share/nginx/html;
    }
}

server {
    listen 80;
    server_name <Your-Site-Name>;
    rewrite     ^ https://<Your-Site-Name>$request_uri? permanent;
}

Include new .conf file to nginx.conf 


Now check the nginx config test by typing below command.

nginx -t


Now restart the nginx service


Now browse your site with https and check whether you are getting "letsencrypt" certificate.



Check your site with sslshopper and ssllabs to verify it further.






Since letsencrypt certificate only valid for 3 month we have to put schedule job to renew. You can add these two lines to crontab.

00 00 * * * /root/letsencrypt/certbot-auto renew
00 01 * * * /bin/systemctl reload nginx

Wednesday, October 21, 2020

NGINX RPM Build with Third-party Modules

 

Prerequisites

  • OS with Centos 7 installed.
  • Enable "epel-release" repo
  • Install below packages
    • openssl openssl-devel gcc gd-devel GeoIP GeoIP-devel libgdata-devel.x86_64 libgdata.x86_64 gcc-c++ flex bison yajl yajl-devel curl-devel curl GeoIP-devel doxygen zlib-devel gcc make automake autoconf libtool pcre pcre-devel libxml2 libxml2-devel curl curl-devel httpd-devel rpm-build.x86_64 rpm-build-libs.x86_64 redhat-lsb-core.x86_64 mhash.x86_64 mhash-devel.x86_64 patch.x86_64 luajit.x86_64 libmodsecurity.x86_64 dkms gcc make kernel-devel bzip2 binutils patch libgomp glibc-headers glibc-devel kernel-headers libXrandr libmodsecurity-devel.x86_64 git mlocate
  • Download and install nginx source RPM from nginx repo (http://nginx.org/packages/centos/7/SRPMS)


Pleased third-party module in side the "/root/rpmbuild/SOURCES/modules"


  • Modules we are going to include are as follow

Build ModSecurity

  • Download ModSecurity from above URL 
  • Execute below commands to build it.
./build.sh

./configure 

 make

make install  


Build LuaJIT

Download the LuaJIT from above URL. Then make the build and install.

make
make install 


Build NGINX with Modules

In some modules, its has patches to apply for nginx source code before build. You can check whether patches are include or not for that module by go through the each module folder. If you fine any patch file you have to patch it.

Ex: 

Apply Patches 

To apply patch you have to first extract the nginx source tar file. It is in "/root/rpmbuild/SOURCES".

Then execute this command

patch -p0 < /root/rpmbuild/SOURCES/modules/nginx-goodies-nginx-sticky/patches/cookies.patch

You have to put full path when it prompt for File path. You find the path from locate command.


Once you applied all the patches, create a tar.gz file of nginx source code. Backup old one before do it.


Then include module you want to build with nginx to nginx.spec file.

















Now it is time build the nginx.
To build the nginx execute this command.

rpmbuild -bb nginx.spec











It will take some time to build the final RPM base on the number of modules you have added.
If you successfully completed the build you will get some thing like this at the end.

Note: If you are a beginner, add module by module and build.















Build RPM is locate under below location.


 




You can install the nginx now.


You can verify available modules by typing nginx -V command.