ELX-VNetwork server
===================

This package is the server and its web panel. The machines themselves run the
client, package elx-vnetwork; both can be installed on the same machine.

What the package puts where
---------------------------

  /opt/elxvnet/elxvnet-server       the program
  /etc/elxvnet/config.json          configuration (created on first install)
  /var/lib/elxvnet/                 database, keys, files offered for download
  elxvnet-server.service            systemd unit, enabled and started

After the first install
-----------------------

The panel listens on port 9191 on every interface:

  http://<server-address>:9191/        the panel, where accounts are registered
  http://<server-address>:9191/admin   the server administrator's pages

Sign in to /admin as admin / admin and change the password straight away —
the administrator pages offer it and keep warning until it is done. Until
then anybody who can reach port 9191 can sign in. From the command line:

  sudo /opt/elxvnet/elxvnet-server -config /etc/elxvnet/config.json -set-password NEW
  sudo systemctl restart elxvnet-server

If a firewall is on, port 9191 has to be opened for this first look
(ufw allow 9191/tcp) — and closed again once nginx is in front.

Before real machines connect: HTTPS
-----------------------------------

Plain HTTP on port 9191 is for trying the server out. In use it belongs behind
nginx on port 443 with a real certificate: the clients' traffic must look like
an ordinary visit to a website, and passwords must not cross the network in
the clear. You need a domain name pointing at this machine.

1. Make the server listen on the loopback interface only. In
   /etc/elxvnet/config.json set

     "addr": "127.0.0.1:9191"

   and run: sudo systemctl restart elxvnet-server

2. Install nginx and certbot, get a certificate:

     sudo apt install nginx certbot
     sudo certbot certonly --webroot -w /var/www/html -d vnet.example.com

3. Take the example site, replace vnet.example.com with your domain, enable it:

     sudo cp /usr/share/doc/elx-vnetwork-server/nginx-example.conf \
             /etc/nginx/sites-available/vnet.example.com
     sudo ln -s /etc/nginx/sites-available/vnet.example.com /etc/nginx/sites-enabled/
     sudo nginx -t && sudo systemctl reload nginx

   Keep the WebSocket headers, the long timeouts and "proxy_buffering off" —
   without them the network either does not come up or drops every minute.

4. Optionally set "publicUrl": "https://vnet.example.com" in config.json. Left
   empty, the server takes the address from each request, which also works.

Clients then join with:

  sudo elxvnet join -server https://vnet.example.com -invite ELX-XXXX-XXXX-XXXX

Mail
----

Registering an account sends a confirmation letter, so the server needs an
SMTP account: /admin, page "Mail". Until it is set, registration is refused.

Updating and removing
---------------------

  sudo apt upgrade            the configuration and the database are kept
  sudo apt remove ...         stops the server, keeps everything
  sudo apt purge ...          also deletes /etc/elxvnet

The database in /var/lib/elxvnet is never deleted by the package: it holds
every account, segment and machine. Remove it by hand if you mean to.

Moving to another machine: /admin, page "Transfer", exports everything into
one file. Copy /var/lib/elxvnet/secrets.key across as well — without it the
saved machine passwords cannot be decrypted.

Supported systems
-----------------

Debian 11 or newer, Ubuntu 20.04 or newer; amd64 and arm64. The program is a
single static binary; what sets the floor is systemd 235, needed by the unit.
