---
title: Web Server Configuration
slug: kronpam-reference-guide-3-5-0/web-server-configuration
description: Learn how to update the configuration files for the Kron PAM SSH connection, server.xml, web.xml, and netright.properties with this detailed guide. Discover how to remove comment tags, modify parameters, and ensure a successful modification by restarting 
docTags: 
createdAt: 2022-08-01T11:40:58.000Z
---

1. Open an SSH connection to Kron PAM with the root account.
2. Open and edit lines 87-111 of the file **/u01/netright-tomcat/conf/server.xml**.
3. Remove the comment tags at the top and bottom. (This is already done.)
4. Change the **keystoreFile**,**&#x20;keystorepass** and **keyAlias** parameters. &#x20;

:::Iframe{iframeHeight="0" code=" <!--&#xA;	<Connector port=&#x22;443&#x22; maxThreads=&#x22;200&#x22; scheme=&#x22;https&#x22; secure=&#x22;true&#x22; SSLEnabled=&#x22;true&#x22; &#xA;		keystoreFile=&#x22;/u01/netright-tomcat/conf/cert/sctest.jks&#x22; keystorePass=&#x22;pass123&#x22; &#xA;		sslEnabledProtocols=&#x22;TLSv1.1,TLSv1.2&#x22;&#xA;		server=&#x22;SingleConnect Server&#x22;&#xA;		ciphers=&#x22;TLS_DHE_RSA_WITH_AES_128_CBC_SHA,&#xA;			TLS_DHE_RSA_WITH_AES_128_CBC_SHA256,&#xA;			TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,&#xA;			TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA,&#xA;			TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,&#xA;			TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,&#xA;			TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,&#xA;			TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,&#xA;			TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,&#xA;			TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA,&#xA;			TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256,&#xA;			TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256,&#xA;			TLS_ECDH_RSA_WITH_AES_128_CBC_SHA,&#xA;			TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256,&#xA;			TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256,&#xA;			TLS_RSA_WITH_AES_128_CBC_SHA,&#xA;			TLS_RSA_WITH_AES_128_CBC_SHA256,&#xA;			TLS_RSA_WITH_AES_128_GCM_SHA256&#x22;&#xA;		clientAuth=&#x22;false&#x22; sslProtocol=&#x22;TLSv1.2&#x22; keyAlias=&#x22;sctest&#x22;/>&#xA; -->&#xA;"}

:::

1. Open and edit lines 4683-4694 of the fil&#x65;**&#x20;/u01/netright-tomcat/conf/web.xml**. Remove the comment tags at the top and bottom.

```html
<!--
<security-constraint>
	<web-resource-collection>
		<web-resource-name>Protected Context</web-resource-name>
		<url-pattern>/*</url-pattern>
	</web-resource-collection>

	<user-data-constraint>
		<transport-guarantee>CONFIDENTIAL</transport-guarantee>
	</user-data-constraint>
</security-constraint>
-->
```

- Open and edit the file,**&#x20;/u01/netright-tomcat/netright/netright.properties**. Change line 18 and add a new property to line 19, as shown below.

:::Iframe{code="18 : netright.baseurl=http://127.0.0.1:80&#xD;&#xA;&#xD;&#xA;change to:as&#xD;&#xA;&#xD;&#xA;18 : netright.baseurl=https://127.0.0.1:443&#xD;&#xA;19 : netright.cookie.secure=true&#xD;&#xA;" iframeHeight="0"}

:::

- Restart the Web Portal service with the command:
  systemctl restart netright-tomcat

