Nginx configuration for connecting to domain.com/owncloud


#1

Hello,

I made a fresh installation of ownCloud 10.0.7 with nginx and everything is working ok
I use a windows client and can connect to cloud2.domain.com/

I have an older owncloud server I moved data and users from. All the windows clients currently connect to this server using cloud.domain.com/owncloud

I want to switch the DNS A record so the clients connecting to the old server connect to the new server (so I don't have to reconfigure all the clients) however if I try to connect to cloud2.domain.com/owncloud from the windows client I get the following error:

05-04 14:51:49:947 [ info sync.networkjob.checkserver ]:	status.php returns:  QJsonDocument()

QNetworkReply::NetworkError(NoError) Reply: QNetworkReplyHttpImpl(0x8c1ad58)
05-04 14:51:49:956 [ warning sync.networkjob.checkserver ]: No proper answer on QUrl("https://removed/login")

I tried setting the location /owncloud in the nginx configuration but I'm not sure I'm doing it right.
Here's the nginx config file

upstream php-handler {
  server 127.0.0.1:9000;
  # Depending on your used PHP version
  #server unix:/var/run/php5-fpm.sock;
  #server unix:/var/run/php7-fpm.sock;

}

server {
listen 85;
server_name cloud.domain.com;

  # For Lets Encrypt, this needs to be served via HTTP
  location /.well-known/acme-challenge/ {
      root /var/www/owncloud; # Specify here where the challenge file is placed
  }

  # enforce https
  location / {
      return 301 https://$server_name$request_uri;
  }

}

server {
listen 443 ssl http2;
server_name cloud.domain.com;

  passenger_enabled off;

  ssl_certificate /etc/nginx/ssl/ssl_certificate.cer;
  ssl_certificate_key /etc/nginx/ssl/cert.key;


  # Add headers to serve security related headers
  # Before enabling Strict-Transport-Security headers please read into this topic first.
  add_header Strict-Transport-Security "max-age=15552000; includeSubDomains";
  add_header X-Content-Type-Options nosniff;
  add_header X-Frame-Options "SAMEORIGIN";
  add_header X-XSS-Protection "1; mode=block";
  add_header X-Robots-Tag none;
  add_header X-Download-Options noopen;
  add_header X-Permitted-Cross-Domain-Policies none;

  # Path to the root of your installation
  root /var/www/owncloud/;

  location = /robots.txt {
      allow all;
      log_not_found off;
      access_log off;
  }


  location = /.well-known/carddav {
      return 301 $scheme://$host/remote.php/dav;
  }
  location = /.well-known/caldav {
      return 301 $scheme://$host/remote.php/dav;
  }

  # set max upload size
  client_max_body_size 512M;
  fastcgi_buffers 8 4K;                     # Please see note 1
  fastcgi_ignore_headers X-Accel-Buffering; # Please see note 2

  error_page 403 /core/templates/403.php;
  error_page 404 /core/templates/404.php;

  location / {
      rewrite ^ /index.php$uri;
  }
  
  location = /owncloud {
      alias /var/www/owncloud/index.php;
  }

  location ~ ^/(?:build|tests|config|lib|3rdparty|templates|data)/ {
      return 404;
  }
  location ~ ^/(?:\.|autotest|occ|issue|indie|db_|console) {
      return 404;
  }

  location ~ ^/(?:index|remote|public|cron|core/ajax/update|status|ocs/v[12]|updater/.+|ocs-provider/.+|core/templates/40[34])\.php(?:$|/) {
      fastcgi_split_path_info ^(.+\.php)(/.*)$;
      include fastcgi_params;
      fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
      fastcgi_param SCRIPT_NAME $fastcgi_script_name; # necessary for owncloud to detect the contextroot https://github.com/owncloud/core/blob/v10.0.0/lib/private/AppFramework/Http/Request.php#L603
      fastcgi_param PATH_INFO $fastcgi_path_info;
      fastcgi_param HTTPS on;
      fastcgi_param modHeadersAvailable true; #Avoid sending the security headers twice
      fastcgi_param front_controller_active true;
      fastcgi_read_timeout 180; # increase default timeout e.g. for long running carddav/ caldav syncs with 1000+ entries
      fastcgi_pass php-handler;
      fastcgi_intercept_errors on;
      fastcgi_request_buffering off; #Available since NGINX 1.7.11
  }

  location ~ ^/(?:updater|ocs-provider)(?:$|/) {
      try_files $uri $uri/ =404;
      index index.php;
  }

  # Adding the cache control header for js and css files
  # Make sure it is BELOW the PHP block
  location ~ \.(?:css|js)$ {
      try_files $uri /index.php$uri$is_args$args;
      add_header Cache-Control "max-age=15778463";
      # Add headers to serve security related headers (It is intended to have those duplicated to the ones above)
      # Before enabling Strict-Transport-Security headers please read into this topic first.
      #add_header Strict-Transport-Security "max-age=15552000; includeSubDomains";
      add_header X-Content-Type-Options nosniff;
      add_header X-Frame-Options "SAMEORIGIN";
      add_header X-XSS-Protection "1; mode=block";
      add_header X-Robots-Tag none;
      add_header X-Download-Options noopen;
      add_header X-Permitted-Cross-Domain-Policies none;
      # Optional: Don't log access to assets
      access_log off;
  }

  location ~ \.(?:svg|gif|png|html|ttf|woff|ico|jpg|jpeg|map)$ {
      add_header Cache-Control "public, max-age=7200";
      try_files $uri /index.php$uri$is_args$args;
      # Optional: Don't log access to other assets
      access_log off;
  }

}

thanks


#2

Have you seen the section "owncloud in a subdir of NGINX" here?
https://doc.owncloud.org/server/latest/admin_manual/installation/nginx_configuration.html

Also your http-server is listening on port 85. Is that desired?


#3

thanks, hadn't read that section.

I tried using that configuration and it works for the client, but now I cannot access owncloud via browser.
with curl I get

curl -i -k https://cloud.domain.ext/owncloud

HTTP/2 302
server: nginx/1.12.2
date: Tue, 08 May 2018 11:33:20 GMT
content-type: text/html; charset=UTF-8
location: /owncloud/
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
x-robots-tag: none
x-download-options: noopen
x-permitted-cross-domain-policies: none


#4

Looks like you have configured a temporary redirect in your nginx configuration. Coukd you post your changed nginx config?


#5

Hi Bernie,

below is my current nginx and owncloud configuration.
I noticed that if I open a browser and try to access owncloud I get the error "ERR_SPDY_INADEQUATE_TRANSPORT_SECURITY", but if I connect to another subdomain on the same server (ie. api.domain.ext) and then connect to cloud2.domain.ext, everything works fine and I see the login page. Clearing the browser cache brings back the issue.

I hope I can get the right formatting :slight_smile:

Nginx

upstream php-handler {
	  server 127.0.0.1:9000;
	  # Depending on your used PHP version
	  #server unix:/var/run/php5-fpm.sock;
	  #server unix:/var/run/php7-fpm.sock;
  }

  server {
	  listen 80;
	  server_name cloud2.domain.ext;

	  # For Lets Encrypt, this needs to be served via HTTP
	  location /.well-known/acme-challenge/ {
		  root /var/www/owncloud; # Specify here where the challenge file is placed
	  }

	  # enforce https
	  location / {
		  return 301 https://$server_name$request_uri;
	  }
  }

  server {
	  listen 443 ssl http2;
	  server_name cloud2.domain.ext;

	  passenger_enabled off;

	  ssl_certificate /etc/nginx/ssl/ssl_certificate.cer;
	  ssl_certificate_key /etc/nginx/ssl/certificate.key;

	  # Example SSL/TLS configuration. Please read into the manual of NGINX before applying these.
	  ssl_session_timeout 5m;
	  ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
	  ssl_ciphers "-ALL:EECDH+AES256:EDH+AES256:AES256-SHA:EECDH+AES:EDH+AES:!ADH:!NULL:!aNULL:!eNULL:!EXPORT:!LOW:!MD5:!3DES:!PSK:!SRP:!DSS:!AESGCM:!RC4";
	  #ssl_dhparam /etc/nginx/dh4096.pem;
	  ssl_prefer_server_ciphers on;
	  keepalive_timeout    70;
	  ssl_stapling on;
	  ssl_stapling_verify on;

	  # Add headers to serve security related headers
	  # Before enabling Strict-Transport-Security headers please read into this topic first.
	  #add_header Strict-Transport-Security "max-age=15552000; includeSubDomains";
	  add_header X-Content-Type-Options nosniff;
	  add_header X-Frame-Options "SAMEORIGIN";
	  add_header X-XSS-Protection "1; mode=block";
	  add_header X-Robots-Tag none;
	  add_header X-Download-Options noopen;
	  add_header X-Permitted-Cross-Domain-Policies none;

	  # Path to the root of your installation
	  root /var/www/;

	  location = /robots.txt {
		  allow all;
		  log_not_found off;
		  access_log off;
	  }

	  location = /.well-known/carddav {
		  return 301 $scheme://$host/owncloud/remote.php/dav;
	  }
	  location = /.well-known/caldav {
		  return 301 $scheme://$host/owncloud/remote.php/dav;
	  }

	  location ^~ /owncloud {

		  # set max upload size
		  client_max_body_size 512M;
		  fastcgi_buffers 8 4K;                     # Please see note 1
		  fastcgi_ignore_headers X-Accel-Buffering; # Please see note 2


		  gzip off;

		  error_page 403 /owncloud/core/templates/403.php;
		  error_page 404 /owncloud/core/templates/404.php;

		  location /owncloud {
			  rewrite ^ /owncloud/index.php$uri;
		  }

		  location ~ ^/owncloud/(?:build|tests|config|lib|3rdparty|templates|data)/ {
			  return 404;
		  }
		  location ~ ^/owncloud/(?:\.|autotest|occ|issue|indie|db_|console) {
			  return 404;
		  }

		  location ~ ^/owncloud/(?:index|remote|public|cron|core/ajax/update|status|ocs/v[12]|updater/.+|ocs-provider/.+|core/templates/40[34])\.php(?:$|/) {
			  fastcgi_split_path_info ^(.+\.php)(/.*)$;
			  include fastcgi_params;
			  fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
			  fastcgi_param SCRIPT_NAME $fastcgi_script_name; # necessary for owncloud to detect the context root https://github.com/owncloud/core/blob/v10.0.0/lib/private/AppFramework/Http/Request.php#L603
			  fastcgi_param PATH_INFO $fastcgi_path_info;
			  fastcgi_param HTTPS on;
			  fastcgi_param modHeadersAvailable true; #Avoid sending the security headers twice
			  # EXPERIMENTAL: active the following if you need to get rid of the 'index.php' in the URLs
			  #fastcgi_param front_controller_active true;
			  fastcgi_read_timeout 180; # increase default timeout e.g. for long running carddav/ caldav syncs with 1000+ entries
			  fastcgi_pass php-handler;
			  fastcgi_intercept_errors on;
			  fastcgi_request_buffering off; #Available since NGINX 1.7.11
		  }

		  location ~ ^/owncloud/(?:updater|ocs-provider)(?:$|/) {
			  try_files $uri $uri/ =404;
			  index index.php;
		  }

		  # Adding the cache control header for js and css files
		  # Make sure it is BELOW the PHP block
		  location ~ /owncloud/.*\.(?:css|js) {
			  try_files $uri /owncloud/index.php$uri$is_args$args;
			  add_header Cache-Control "max-age=15778463";
			  # Add headers to serve security related headers  (It is intended to have those duplicated to the ones above)
			  # Before enabling Strict-Transport-Security headers please read into this topic first.
			  #add_header Strict-Transport-Security "max-age=15552000; includeSubDomains";
			  add_header X-Content-Type-Options nosniff;
			  add_header X-Frame-Options "SAMEORIGIN";
			  add_header X-XSS-Protection "1; mode=block";
			  add_header X-Robots-Tag none;
			  add_header X-Download-Options noopen;
			  add_header X-Permitted-Cross-Domain-Policies none;
			  # Optional: Don't log access to assets
			  access_log off;
		  }

		  location ~ /owncloud/.*\.(?:svg|gif|png|html|ttf|woff|ico|jpg|jpeg|map) {
			  try_files $uri /owncloud/index.php$uri$is_args$args;
			  add_header Cache-Control "public, max-age=7200";
			  # Optional: Don't log access to other assets
			  access_log off;
		  }
	  }
  }

config.php

<?php
$CONFIG = array (
  'updatechecker' => false,
  'instanceid' => 'ocrwd1tmrm2a',
  'passwordsalt' => 'removed',
  'secret' => 'removed',
  'trusted_domains' =>
  array (
	0 => 'removed',
	1 => 'removed',
	2 => 'removed',
  ),
  'datadirectory' => '/Owncloud',
  'overwrite.cli.url' => 'https://ipaddress/owncloud',
  'dbtype' => 'mysql',
  'version' => '10.0.7.2',
  'dbname' => 'ownCloud',
  'dbhost' => 'localhost',
  'dbtableprefix' => 'oc_',
  'mysql.utf8mb4' => true,
  'dbuser' => 'removed',
  'dbpassword' => 'removed',
  'logtimezone' => 'UTC',
  'installed' => true,
);

#6

I commented this line and it's working now, I will check what that means and figure it out

thanks for the help


#7

Instead of
ssl_ciphers "-ALL:
it should be:
ssl_ciphers "ALL: