Skip to main content

BriefCam Installation Guide

Installing and Configuring NGINX

Last Updated: 6 minute read
Version2025r1
LanguageEnglish

This section describes the steps to take to use NGINX.

Note

To work with SSL and BriefCam, using a load balancer is required. BriefCam recommends using NGINX.

Recommendations

It is recommended to install the load balancer on a separate machine.

If you are working in a virtualized environment, the load balancer must be on a separate machine.

If you are working in a non-virtualized (physical servers) environment, you can have the load balancer on the same machine as the Web Services (although it is not recommended). However, if you install the load balancer on the same machine as the Web Services, IIS has to work on a different port (not 80, since 80 is for NGINX).

Important

It is recommended not to make manual changes to the NGINX configuration file. However, if you do make changes, ensure that all modifications comply with valid NGINX syntax and all endpoint names are used exactly as defined, including case sensitivity.

Prerequisites

  • Make sure that ports 80 and 443 are not in use by another application.

  • If IIS is installed, make sure to stop it or change its default port.

Steps

  1. To run the BriefCam NGINX Installation wizard, right-click on the BriefCamNGINX_<Version number>.exe file and select Run as administrator.

    If you are using the latest Windows Update and a Windows Defender alert appears, click the More info link and click Run anyway.

    Windows protected your PC4.png
  2. In the Welcome screen, click Get Started.

    NGINX_welcome.png
  3. Accept the terms of the BriefCam license agreement and click Next.

    NGINX_license_2.png
  4. Read the license agreement and click Next.

    NGINX_license_1.png
  5. Enter the IP address or the hostname (if there is a DNS resolution) for each of the relevant services below, and click Next. Note that once you enter the Research host, you can click the “Click to use the RESEARCH host for all service” button to fill in all the fields with this value.

    NGINX_services_configuration.png
  6. Decide whether to run with a secure communication.

    NGINX_using_HTTPS.png
  7. If you check the checkbox, enter the paths to the certificate and private key.

    Note

    You need to create or use an existing self-signed certificate separated into two files: .crt and .key.

  8. If your SSL certificate is protected by a password, you need to configure NGINX to read a list of passwords that are stored in a separate file. If the private key is not in this file, NGINX will not start. You do this as follows:

    1. Create a new text file named ssl_passwords.txt and save it to a separate folder than where the SSL certificate is located.

    2. Set the file to be readable only to the user running NGINX.

    3. Enter the certificate password into the first line of the ssl_passwords.txt file.

    4. In the nginx config file, add the following line above the existing certificate lines: 

      ssl_password_file /var/lib/nginx/ssl_passwords.txt; 

    5. Distribute this file separately from the configuration file. 

  9. Click Next.

    The following screen appears.

    NGINX_Database_fields.png
  10. In the Database Host and Database Port fields, enter the name and port of the machine where you installed PostgreSQL.

  11. In the Application User and Application Password fields, enter the username and password that you entered when installing PostgreSQL.

  12. Click the Test Database Connection button.

  13. Click Next.

  14. Confirm or select the drive where you want to install NGINX and click Install.

    NGINX_install_path.png
  15. If you have more than one web service hostname, after installing NGINX, open the nginx.conf file (located by default at: C:/nginx/conf) and in the http section, copy and paste the existing rows and update the new rows with the additional hostnames.

  16. On any host that is running the application (browser) make sure the domains (or host name) can be resolved by the DNS. If no DNS is available, you can edit the hosts file and add the IP address of the load balancer using the following syntax:

    10.x.x.x www.example.com example.com

    For example: 10.0.0.143 www.example.com

  17. Open the following three web config .js files on the BriefCam server (by default these three files are at C:\Program Files\BriefCam\WebServices):

    • \app\webConfig.js 

    • \ProWebAdminClient\web.config.js 

    • \ProWebClient\webConfig.js 

      NGINX Webconfig files.png
  18. In each of the three web config .js files, set the endpoints (endPointApi) to point to the load balancer. In the example below, you would just change PRODUCT1 to the address of the load balancer. Make sure that “http:” does not appear in the path.

    Web config endpoint.png
  19. Open the QLIK QMC with the user that was used to install the RESEARCH module (https://<hostname>/qmc).

  20. Browse to virtual proxies and add two new parameters using the hostname of each of the machines (for example, the QLIK machine and the NGINX machine host names as shown in the image below) to both proxies:

    • Virtual Proxies->bc->advanced->Host white list

    • Virtual Proxies->Central Proxy (Default)->advanced->Host white list

      Host white list.png

      Note

      On some systems, you might be required to add the host name, FQDN and IP address of the load balancer and all the web services instances into the virtual proxies white list in QMC.

  21. In the User directory connectors screen, go to the Visible connection string and add the domain name to the server value. For example, in the image below, Stress-DB was the original value and now it is Stress-DB.briefcamdev.com.

    Qlik User directory connectors.png
  22. Open the BriefCam Administrator Console.

  23. If you selected to use a secured connection (https), set the DefaultSiteProtocol environment setting to https.

  24. Check that the following environment settings are set to the NGINX IP address or FQDN and make sure that the URLs begin with http:// or https:// (if you selected to use a secured connection:

    • BaseVideoUrl 

    • clientNotificationEndPoint 

    • CommonPlatformAPI.ServiceURL 

    • DB.LocalStorageAddress 

    • LoadBalancerAddress – This setting should be set to the NGINX hostname (FQDN)

    • ProWebApiAddress 

    • ProWebClientAddress 

    • QlikServer 

    • Site.Url 

    • StorageGatewayUrl 

    • SSOEndpoint – If you want to use an embedded client, this value should be set to: http[s]://<NGINX-host>:8030/MilestoneSSO/

  25. If you are installing a Linux-based OX engine, make sure that the value for the OX6.EngineOutputGatewayGrpcPort environment setting matches what you entered in the installer’s Processing box (default 49149).

  26. If you are installing a Linux-based OX engine, make sure that the value for OX6.VmsAdapterGrpcPort environment setting matches what was entered in the installer’s VMS Agent box (default 49151).

    NGINX_ports_check.png
  27. Restart the BriefCam services.

  28. If you selected to use a secured connection (https), browse to the application and check that it works with https requests. For example:

    • https://www.example.com/app

    • https://www.example.com/admin

NGINX Windows Service

The BriefCam NGINX installer creates a BriefCam NGINX Web Server service in the Windows Services screen. This service is responsible for making sure the NGINX process is constantly running and the load balancer is ready to accept requests. The user that runs this service is the BriefCam Windows user.

NGINX Web Server.png

Generic Configurations

For any other type of load balancer, such as Amazon ELB, Google Cloud Platform Load Balancer and so on, you need to configure redirect rules based on the URL. The following are the redirect rules:

1. Notification Service

Search for: /signalr

Redirect to: notification-server:7080

2. Video Streaming Gateway

Search for: /vsg

Use rewrite rule to remove /vsg from the URL

Redirect to: videostreaming-server:5010

3. Research (Qlik)

Search for: /bc/

Redirect to: www.example.com:8090

4. Web Services

Search for: /

Redirect to: briefcam-webserver

5. Storage Gateway (if used)

Search for: /StorageGateway

Redirect to: storage gateway server:5012

6. Hub BI Gateway (for multisite)

Search for: /hubbigateway

Redirect to server where the Hub BI Gateway is running, port 5007

7. Outbound API Gateway (for multisite)

Search for: /outboundapigateway

Redirect to server where the Outbound API Gateway is running, port: 5005

8. Common Platform API

Search for: /commonplatformapi/

Redirect to server where the Common Platform API service is running, port 5014

9. Task Management

Search for: /taskmanagement

Redirect to server where the Task Management service is running, port 5013