| Audience: DocuShare administrators |
Configure HTTPS for DocuShare on Windows and Linux
Overview
HTTPS is provided by the web server in front of DocuShare. The web server handles the TLS certificate and encrypted browser connection; DocuShare must also be configured to generate secure https:// links. The Administrator Guide describes IIS on Windows and Apache on Linux.
This procedure changes web access and service settings. Coordinate it with your web-server administrator and perform it during a maintenance window.
Before You Begin
- Confirm the DocuShare version, operating system, web server, and supported configuration for your release.
- Obtain and install a valid TLS certificate using the official IIS or Apache documentation for your environment.
- Back up the web-server configuration and DocuShare configuration.
- Confirm that you can access the server locally or through an alternate administrative path before changing ports.
- Plan to test sign-in, links, redirects, and integrations after restarting services.
Configure the Web Server
1. Configure IIS (Windows) or Apache (Linux) for HTTPS using the web-server vendor's instructions.
2. Verify that the certificate chain and hostname are valid from a browser before changing DocuShare settings.
Update DocuShare and Restrict Direct Tomcat HTTP Access
DocuShare should use HTTPS-based addresses, and the Tomcat HTTP servlet port should not remain directly available to browsers when the front-end web server is providing secure access.
### Windows with IIS
1. Open a Command Prompt in <DSHome>\bin with the required administrative permissions.
2. Stop DocuShare using the site's standard service procedure.
3. Run dssetup and set the Tomcat HTTP port status to off.
4. Start DocuShare. If IIS is running as a service, follow the Guide's instruction to reboot the system after configuration.
### Linux with Apache
1. Sign in to the server with the required system-administrator privileges and change to <DSHome>/bin.
2. Stop DocuShare with ./stop_docushare.sh.
3. Run ./start_docushare.sh tomcat http off to close the Tomcat HTTP port.
4. Start DocuShare using the documented startup procedure for your deployment.
The guide documents ./start_docushare.sh tomcat http on as the way to reopen the Tomcat HTTP port. Do not reopen it in a production configuration unless the security design explicitly requires it and the exposure is understood.
Validate HTTPS
1. Browse to the site using its HTTPS address and confirm the certificate is valid.
2. Sign in and test representative pages and links. Confirm that DocuShare generates HTTPS URLs.
3. Confirm that direct browser access to the Tomcat HTTP port is blocked as intended.
4. Test integrations, callbacks, and mobile access that depend on the site URL.
If validation fails, restore the backed-up configuration and contact DocuShare Support or the web-server administrator. Certificate renewal and cipher/protocol configuration are managed according to the web-server documentation and current security policy.