1
00:00:00,227 --> 00:00:01,637
- [Instructor] Hi, and welcome back.

2
00:00:01,637 --> 00:00:03,875
In this video we're going
to be setting up Nginx

3
00:00:03,875 --> 00:00:08,098
with SSL and getting it
serving SDPS requests.

4
00:00:08,098 --> 00:00:10,719
If you go to Postman now
and try to access your site

5
00:00:10,719 --> 00:00:15,369
or your API using HTTPS, you'll
see it connection timeout.

6
00:00:15,369 --> 00:00:18,147
So that's good because we
have not set it up yet,

7
00:00:18,147 --> 00:00:20,001
but we're going to do that in this video.

8
00:00:20,001 --> 00:00:24,001
The first thing to do is
to go into your server,

9
00:00:24,886 --> 00:00:26,680
and there we are.

10
00:00:26,680 --> 00:00:28,805
And then we're going to go into

11
00:00:28,805 --> 00:00:32,026
we're going to look at
the contents of /var/www,

12
00:00:32,026 --> 00:00:35,492
and as you can see, we've
got the html folder,

13
00:00:35,492 --> 00:00:38,374
and that contains our API,

14
00:00:38,374 --> 00:00:42,352
but we're going to make a
directory inside /var/www,

15
00:00:42,352 --> 00:00:45,875
which I'm going to call /ssl.

16
00:00:45,875 --> 00:00:48,042
And of course I have to be

17
00:00:50,163 --> 00:00:52,357
admin for that.

18
00:00:52,357 --> 00:00:53,933
So we've created the directory,

19
00:00:53,933 --> 00:00:57,094
and now what we're going to
do is create two files in it.

20
00:00:57,094 --> 00:00:58,644
One is going to contain the key,

21
00:00:58,644 --> 00:01:02,120
and the other one is going
to contain the certificate.

22
00:01:02,120 --> 00:01:06,287
So
sudo
touch
/var/www/ssl/rest-api-course-trial.com.pem,

23
00:01:11,748 --> 00:01:16,266
so that's just the domain,
.pem, and that's going to be

24
00:01:16,266 --> 00:01:18,291
the certificate.

25
00:01:18,291 --> 00:01:21,321
And similarly, the same,
but instead of .pem,

26
00:01:21,321 --> 00:01:25,791
it's going to be .key
is going to be the key.

27
00:01:25,791 --> 00:01:29,014
And then we're going to go ahead and do

28
00:01:29,014 --> 00:01:33,181
sudo vi /var/www/ssl/

29
00:01:34,996 --> 00:01:37,931
We're going to modify the .pem file,

30
00:01:37,931 --> 00:01:39,019
and in here we're going to

31
00:01:39,019 --> 00:01:42,781
paste the contents of our certificate,

32
00:01:42,781 --> 00:01:45,463
so I'm going to go over to Chrome,

33
00:01:45,463 --> 00:01:46,847
and I'm going to select everything,

34
00:01:46,847 --> 00:01:50,644
including the BEGIN CERTIFICATE
and END CERTIFICATE,

35
00:01:50,644 --> 00:01:53,891
so everything there, everything
that's inside the grey box.

36
00:01:53,891 --> 00:01:56,634
We're going to select it all and copy it

37
00:01:56,634 --> 00:01:57,967
and then we're going to go here,

38
00:01:57,967 --> 00:01:59,543
and if you're using vim like me,

39
00:01:59,543 --> 00:02:03,687
what you have to do is
press the I key for insert,

40
00:02:03,687 --> 00:02:07,270
the I key, and then
you can paste in there.

41
00:02:08,459 --> 00:02:11,063
Do not, naturally, as
obvious as this sounds,

42
00:02:11,063 --> 00:02:14,310
attempt to paste this in manually.

43
00:02:14,310 --> 00:02:17,810
That would be not a good use of your time.

44
00:02:18,908 --> 00:02:22,173
So once you've got that, I'm
going to press the Escape key,

45
00:02:22,173 --> 00:02:24,840
and then :wq for write and quit,

46
00:02:28,067 --> 00:02:29,774
and that's that.

47
00:02:29,774 --> 00:02:33,318
Then we're going to do the
same, but with the key.

48
00:02:33,318 --> 00:02:34,789
Once again, going over to Chrome.

49
00:02:34,789 --> 00:02:36,792
Instead of the certificate,

50
00:02:36,792 --> 00:02:39,625
now we're going to select the key,

51
00:02:40,928 --> 00:02:41,761
and we're going to make sure

52
00:02:41,761 --> 00:02:43,440
that we've got everything selected,

53
00:02:43,440 --> 00:02:45,948
including BEGIN PRIVATE
KEY and END PRIVATE KEY.

54
00:02:45,948 --> 00:02:48,064
We're going to select
everything in the grey box,

55
00:02:48,064 --> 00:02:50,101
we're going to copy it,
we're going to go over here,

56
00:02:50,101 --> 00:02:53,454
we're going to press the I key for insert,

57
00:02:53,454 --> 00:02:54,873
we're going to paste,

58
00:02:54,873 --> 00:02:56,858
and then we're going to
press the Escape key,

59
00:02:56,858 --> 00:02:59,108
and :wq for write and quit.

60
00:03:02,248 --> 00:03:05,853
We've got now our certificate
and key in the server.

61
00:03:05,853 --> 00:03:10,020
We can go back to Chrome
and just press OK down here.

62
00:03:11,339 --> 00:03:13,220
And now our certificate is there.

63
00:03:13,220 --> 00:03:16,238
It expires in 2032, which
is a pretty long time,

64
00:03:16,238 --> 00:03:19,528
and we're done with this section here.

65
00:03:19,528 --> 00:03:22,028
Do notice that the SSL setting

66
00:03:24,213 --> 00:03:27,296
may take up to 24 hours to be active.

67
00:03:29,524 --> 00:03:31,353
Let's go back to the terminal.

68
00:03:31,353 --> 00:03:32,380
And now what we're going to do

69
00:03:32,380 --> 00:03:36,325
is serve the HTTPS traffic using Nginx.

70
00:03:36,325 --> 00:03:39,325
So what we're going to do is over to

71
00:03:40,321 --> 00:03:44,488
/etc/nginx/sites-enable/items-rest.conf,

72
00:03:45,729 --> 00:03:48,837
which is my configuration file.

73
00:03:48,837 --> 00:03:52,198
And here, as you remember,
we've got our server.

74
00:03:52,198 --> 00:03:54,715
And that's listening on port 80.

75
00:03:54,715 --> 00:03:57,048
Port 80 is for HTTP traffic.

76
00:03:58,485 --> 00:04:00,793
We're going to listen
for a different port,

77
00:04:00,793 --> 00:04:03,805
which is for HTTPS traffic.

78
00:04:03,805 --> 00:04:06,130
You may also have some
extra lines down here.

79
00:04:06,130 --> 00:04:07,515
These are for errors.

80
00:04:07,515 --> 00:04:09,883
I don't have them in here,
because this is just an example,

81
00:04:09,883 --> 00:04:14,472
but you may have them and
that's fine, you can keep them.

82
00:04:14,472 --> 00:04:16,389
All we've got to do is,

83
00:04:17,284 --> 00:04:18,542
instead of listen 80,

84
00:04:18,542 --> 00:04:21,572
we're going to remove the 80,

85
00:04:21,572 --> 00:04:23,035
and we're going to insert there,

86
00:04:23,035 --> 00:04:25,085
using the I key,

87
00:04:25,085 --> 00:04:26,668
443 default_server.

88
00:04:29,479 --> 00:04:30,404
And all that's doing

89
00:04:30,404 --> 00:04:35,268
is that it's going to listen
on port 443 by default.

90
00:04:35,268 --> 00:04:36,783
So the first thing that it's going to do

91
00:04:36,783 --> 00:04:38,176
when a request comes in

92
00:04:38,176 --> 00:04:41,224
is it's going to see if it's on port 443,

93
00:04:41,224 --> 00:04:42,391
and that's it.

94
00:04:43,549 --> 00:04:45,264
The next thing we're going to do is

95
00:04:45,264 --> 00:04:47,597
we're going to set

96
00:04:47,597 --> 00:04:48,764
a server_name,

97
00:04:49,704 --> 00:04:54,198
and that's going to be
rest-api-course-trial.com

98
00:04:54,198 --> 00:04:55,508
Notice that the number of spaces

99
00:04:55,508 --> 00:04:57,676
between the setting and the value

100
00:04:57,676 --> 00:05:01,259
doesn't matter as long
as it's one or more.

101
00:05:02,752 --> 00:05:04,921
And similarly, the spaces
at the front don't matter,

102
00:05:04,921 --> 00:05:08,543
but I like to keep them so
that it's easier to read.

103
00:05:08,543 --> 00:05:11,486
We're going to set ssl to on.

104
00:05:11,486 --> 00:05:15,570
We're going to set
ssl_certificate to the key

105
00:05:15,570 --> 00:05:20,241
sorry, the certificate file,
apologies, that we've created.

106
00:05:20,241 --> 00:05:21,166
That's going to be

107
00:05:21,166 --> 00:05:25,333
/var/www/ssl/rest-api-course-trial.com.pem;

108
00:05:29,140 --> 00:05:33,307
And finally, ssl_certificate_key
is going to be the key.

109
00:05:39,735 --> 00:05:42,719
And hopefully I'm not making any typos.

110
00:05:42,719 --> 00:05:46,829
I do get a lot of questions
from students like yourself

111
00:05:46,829 --> 00:05:48,484
which make small typos.

112
00:05:48,484 --> 00:05:50,025
Make sure to double-check this.

113
00:05:50,025 --> 00:05:51,984
It's important, or else nothing will work,

114
00:05:51,984 --> 00:05:54,544
rest-api-course-trial.com,
rest-api-course-trial.com,

115
00:05:54,544 --> 00:05:56,461
this all looks correct.

116
00:05:57,774 --> 00:05:58,776
And that's it.

117
00:05:58,776 --> 00:05:59,609
So now,

118
00:06:01,945 --> 00:06:04,714
if we save and quit
this and restart Nginx,

119
00:06:04,714 --> 00:06:05,828
everything's working.

120
00:06:05,828 --> 00:06:09,477
However, we've got a
server listening on 443,

121
00:06:09,477 --> 00:06:10,774
and nothing listening on 80,

122
00:06:10,774 --> 00:06:13,116
which means we've got HTTPS to work,

123
00:06:13,116 --> 00:06:17,287
but HTTP is not working now,
which can sometimes be okay.

124
00:06:17,287 --> 00:06:21,571
Sometimes you just want
everything to go onto HTTPS.

125
00:06:21,571 --> 00:06:22,808
And we do want that,

126
00:06:22,808 --> 00:06:26,596
but we don't want to give
our HTTP users an error.

127
00:06:26,596 --> 00:06:28,929
So after this server, which,

128
00:06:29,870 --> 00:06:32,621
notice how there's an opening brace there

129
00:06:32,621 --> 00:06:35,486
and a closing brace
down there, which match.

130
00:06:35,486 --> 00:06:36,792
Similarly there's an opening brace here

131
00:06:36,792 --> 00:06:38,271
and a closing brace here.

132
00:06:38,271 --> 00:06:40,770
So after the entire server block,

133
00:06:40,770 --> 00:06:42,345
we're going to go down here,

134
00:06:42,345 --> 00:06:45,580
and we're going to have
another server block.

135
00:06:45,580 --> 00:06:50,399
And in this server block, we're
going to listen on port 80.

136
00:06:50,399 --> 00:06:53,257
And similarly, the server_name
is going to be the same,

137
00:06:53,257 --> 00:06:55,424
rest-api-course-trial.com,

138
00:06:56,749 --> 00:06:58,090
but we're going to tell it

139
00:06:58,090 --> 00:07:01,194
that whenever a request
comes onto port 80,

140
00:07:01,194 --> 00:07:03,277
which is an HTTP request,

141
00:07:04,198 --> 00:07:07,803
to send it over to the HTTPS equivalent.

142
00:07:07,803 --> 00:07:10,303
So we're going to say rewrite,

143
00:07:13,265 --> 00:07:15,598
and here is this thing here,

144
00:07:17,192 --> 00:07:20,405
which I'm going to explain what it is.

145
00:07:20,405 --> 00:07:23,655
Everything from the first forward slash

146
00:07:28,913 --> 00:07:30,741
after, naturally, the server_name--

147
00:07:30,741 --> 00:07:32,753
My apologies, that wasn't clear.

148
00:07:32,753 --> 00:07:35,696
So everything after the server_name,

149
00:07:35,696 --> 00:07:36,958
starting with the slash,

150
00:07:36,958 --> 00:07:38,848
is going to get rewritten into

151
00:07:38,848 --> 00:07:43,015
https://rest-api-course-trial.com/$1

152
00:07:48,235 --> 00:07:50,864
So what's happening here is

153
00:07:50,864 --> 00:07:52,031
request comes in, which is

154
00:07:52,031 --> 00:07:56,811
http://rest-api-course-trial.com/something

155
00:07:56,811 --> 00:07:59,816
and that something is what
we're requesting on an API.

156
00:07:59,816 --> 00:08:02,602
And what this rewrite
is doing is it's saying,

157
00:08:02,602 --> 00:08:05,841
everything that is after the slash,

158
00:08:05,841 --> 00:08:08,270
it doesn't include the
rest-api-course-trial.com,

159
00:08:08,270 --> 00:08:11,823
so, everything after the slash,
we're going to select it,

160
00:08:11,823 --> 00:08:12,737
that's what the bracket means,

161
00:08:12,737 --> 00:08:15,985
select the stuff after the slash,

162
00:08:15,985 --> 00:08:19,457
and that is then replaced by $1 here.

163
00:08:19,457 --> 00:08:23,253
So it's rewriting everything
that's after the slash into

164
00:08:23,253 --> 00:08:27,420
https://rest-api-course-trial.com/whatever
we requested.

165
00:08:29,183 --> 00:08:30,183
And finally,

166
00:08:32,587 --> 00:08:35,717
permanent, which means
that future requests

167
00:08:35,717 --> 00:08:38,717
are going to continue on server 443.

168
00:08:40,717 --> 00:08:45,567
And it's going to rewrite
the browser URL as well.

169
00:08:45,567 --> 00:08:47,144
That's pretty much everything.

170
00:08:47,144 --> 00:08:48,877
Let's have a quick final check,

171
00:08:48,877 --> 00:08:52,342
make sure we've not missed anything.

172
00:08:52,342 --> 00:08:54,685
And we've got listen, server_name,

173
00:08:54,685 --> 00:08:57,628
ssl on, certificate and key.

174
00:08:57,628 --> 00:09:01,703
Oh, we've got a duplicate
server_name here.

175
00:09:01,703 --> 00:09:03,566
We can delete that.

176
00:09:03,566 --> 00:09:05,649
It's not really a problem

177
00:09:06,553 --> 00:09:09,386
but it's better if it's not there.

178
00:09:10,924 --> 00:09:13,676
And we also have a
missing semicolon there.

179
00:09:13,676 --> 00:09:16,662
This is actually a problem;
that's quite important.

180
00:09:16,662 --> 00:09:17,699
And I think that's it.

181
00:09:17,699 --> 00:09:19,989
So hopefully we've not
got any errors there.

182
00:09:19,989 --> 00:09:24,020
Let's press the Escape
key, :wq for save and quit,

183
00:09:24,020 --> 00:09:27,686
and we are ready to do a restart of Nginx.

184
00:09:27,686 --> 00:09:28,853
And that's it.

185
00:09:30,220 --> 00:09:32,458
However, before continuing,

186
00:09:32,458 --> 00:09:35,541
make sure to do sudo ufw allow https.

187
00:09:37,839 --> 00:09:42,585
And now it's likely that this
won't make any difference,

188
00:09:42,585 --> 00:09:46,459
but in some cases I've seen that the ufw,

189
00:09:46,459 --> 00:09:48,810
which is the open to firewall,

190
00:09:48,810 --> 00:09:51,910
has been rejecting https requests,

191
00:09:51,910 --> 00:09:54,148
which just makes everything fail.

192
00:09:54,148 --> 00:09:56,682
So just do that just in case.

193
00:09:56,682 --> 00:09:58,554
And as you can see, I've
already got it there,

194
00:09:58,554 --> 00:10:02,185
but if your set rule added,
then it was worth it,

195
00:10:02,185 --> 00:10:05,981
and do sudo ufw reload
for good measure as well.

196
00:10:05,981 --> 00:10:09,882
That will just reload the
firewall configuration.

197
00:10:09,882 --> 00:10:14,532
And then we can do sudo
systemctl reload nginx

198
00:10:14,532 --> 00:10:17,457
sudo systemctl restart
nginx for good measure,

199
00:10:17,457 --> 00:10:19,843
even though this is not really necessary.

200
00:10:19,843 --> 00:10:22,593
And finally, we can go to Postman

201
00:10:23,500 --> 00:10:27,697
and make sure that you have
the HTTPS URL selected there

202
00:10:27,697 --> 00:10:30,066
in your environment.

203
00:10:30,066 --> 00:10:34,489
And you can send the request
and see that it works.

204
00:10:34,489 --> 00:10:36,893
Since this request works,
we know that all of them do,

205
00:10:36,893 --> 00:10:38,673
because we've not really
changed the API itself,

206
00:10:38,673 --> 00:10:40,832
we've only changed the sort of interface,

207
00:10:40,832 --> 00:10:42,400
the way it connects,

208
00:10:42,400 --> 00:10:45,369
so we don't have to test every endpoint.

209
00:10:45,369 --> 00:10:46,202
And that's it.

210
00:10:46,202 --> 00:10:48,321
You've got SSL, and now what that means

211
00:10:48,321 --> 00:10:52,488
is that the connection between
your computer and Cloudflare

212
00:10:53,492 --> 00:10:56,492
is encrypted using your private key.

213
00:10:59,905 --> 00:11:03,989
So if you want to understand
more about what SSL is,

214
00:11:03,989 --> 00:11:07,237
that's a bit outside the
scope of this course,

215
00:11:07,237 --> 00:11:10,189
but I will include some
resources in the next lecture

216
00:11:10,189 --> 00:11:11,774
to help you understand a bit more

217
00:11:11,774 --> 00:11:14,856
about what SSL is and how it works.

218
00:11:14,856 --> 00:11:15,988
It's quite an advanced thing.

219
00:11:15,988 --> 00:11:17,904
It's all about cryptography.

220
00:11:17,904 --> 00:11:19,332
But nevertheless, I find
it quite interesting,

221
00:11:19,332 --> 00:11:20,951
and maybe you do too.

222
00:11:20,951 --> 00:11:21,784
But if you're not interested

223
00:11:21,784 --> 00:11:25,499
in the insides of how this process works,

224
00:11:25,499 --> 00:11:27,347
and all the technicalities,

225
00:11:27,347 --> 00:11:29,750
then just know that now your
connections to Cloudflare

226
00:11:29,750 --> 00:11:31,431
are secure.

227
00:11:31,431 --> 00:11:34,905
And since you're using
Cloudflare's own SSL certificate,

228
00:11:34,905 --> 00:11:39,198
and we've selected the
strict SSL connection,

229
00:11:39,198 --> 00:11:41,183
the connection between
Cloudflare and your server

230
00:11:41,183 --> 00:11:44,016
is also encrypted and also secure.

231
00:11:45,336 --> 00:11:49,873
So yeah, you have now added
security to your server.

232
00:11:49,873 --> 00:11:52,059
Hopefully that was not too complicated,

233
00:11:52,059 --> 00:11:54,706
quite straightforward, and
if you have any problems,

234
00:11:54,706 --> 00:11:57,031
just go ahead and ask in the course Q&A.

235
00:11:57,031 --> 00:12:00,302
And otherwise, I'll see
you in the next one.

