# Flexisip:ファイル転送サーバ・カンファレンスサーバ構築メモ

**URL:** https://forum.ficusonline.com/t/topic/510
**Category:** Server
**Created:** [2024 年 5 月 10 日午後 2:56 UTC](https://forum.ficusonline.com/t/topic/510 "2024-05-10T14:56:34Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2024 年 5 月 10 日午後 2:56 UTC](https://forum.ficusonline.com/t/topic/510/1 "2024-05-10T14:56:34Z")

</div>

## ファイル転送サーバ

### Flexisip http file transfer server

[https://gitlab.linphone.org/BC/public/flexisip-http-file-transfer-server](https://gitlab.linphone.org/BC/public/flexisip-http-file-transfer-server)

ApacheコンテナとPHP-FPMコンテナからファイル転送サーバを構築

**Apache httpd コンテナイメージ**

> **[httpd - Official Image | Docker Hub](https://hub.docker.com/_/httpd)**
>
> The Apache HTTP Server Project

**Apache + PHP-FPM**  
[Apache HTTP Server - ArchWiki](https://wiki.archlinux.org/title/Apache_HTTP_Server)

**Apache httpd設定ファイル**

`/etc/httpd/conf/httpd.conf`

```auto
LoadModule proxy_module modules/mod_proxy.so 
LoadModule proxy_fcgi_module modules/mod_proxy_fcgi.so

<FilesMatch \.php$>
    SetHandler "proxy:fcgi://192.xx.xx.xx:9000"
</FilesMatch>

```

**TLS認証方法（参考）**

Two authentication methods are supported:

- **TLS authentication:** allows to accept or refuse a request based on a potential client certificate.
- **Digest authentication** : checks the password of the sender by using a password database (see [Digest Access Authentication](https://en.wikipedia.org/wiki/Digest_access_authentication)).

> **[Authentication - XWiki](https://wiki.linphone.org/xwiki/wiki/public/view/Flexisip/Configuration/Authentication/)**
>
> Authentication

> **[TLS client authentication - XWiki](https://wiki.linphone.org/xwiki/wiki/public/view/Linphone/TLS%20client%20authentication/)**
>
> TLS client authentication

* * *

* * *

**注）PHPでダイジェスト認証するため、以下のApacheモジュールは不要。**

### [mod\_auth\_digest - Apache HTTP Server Version 2.4](https://httpd.apache.org/docs/2.4/mod/mod_auth_digest.html)

### [mod\_authn\_dbd - Apache HTTP Server Version 2.4](https://httpd.apache.org/docs/2.4/mod/mod_authn_dbd.html)

### [mod\_authn\_socache - Apache HTTP Server Version 2.5](https://httpd.apache.org/docs/trunk/mod/mod_authn_socache.html)

* * *

> <https://stackoverflow.com/questions/75809457/alpine-linux-apache2-var-www-modules-apr-dbd-mysql-so-my-init-symbol-not-foun>

* * *

* * *

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2024 年 5 月 14 日午前 2:17 UTC](https://forum.ficusonline.com/t/topic/510/2 "2024-05-14T02:17:10Z")

</div>

Apacheで`proxy_fcgi` を使用している場合、特定のHTTPヘッダー（例えば、`Authorization` ヘッダー）がPHP-FPMに正しく渡されないことがあります。これを解決するためには、`SetEnvIf` ディレクティブや`ProxyPass` オプションを使用してヘッダーを適切に渡す設定を行う必要があります。  
（ **BearerトークンやBasic認証のヘッダーをPHPで取得したい場合** ）

### 1. `SetEnvIf`ディレクティブの使用

```auto
<VirtualHost *:80>
    ServerName your-domain.com
    DocumentRoot /var/www/html

    <Directory /var/www/html>
        Require all granted
    </Directory>

    # Set up the environment variable for the Authorization header
    SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1

    # Proxy settings
    <FilesMatch \.php$>
        SetHandler "proxy:unix:/var/run/php/php-fpm.sock|fcgi://localhost"
    </FilesMatch>
</VirtualHost>

```

### 2. `ProxyPass`オプションの使用

```auto
<VirtualHost *:80>
    ServerName your-domain.com
    DocumentRoot /var/www/html

    <Directory /var/www/html>
        Require all granted
    </Directory>

    # Pass Authorization header to PHP-FPM
    <Proxy "unix:/var/run/php/php-fpm.sock|fcgi://localhost">
        ProxySet env=Authorization
    </Proxy>

    # Proxy settings
    ProxyPassMatch ^/(.*\.php(/.*)?)$ "unix:/var/run/php/php-fpm.sock|fcgi://localhost/$1"
</VirtualHost>

```

### 3. `RewriteRule`を使用する方法(mod\_rewrite)

```auto
<VirtualHost *:80>
    ServerName your-domain.com
    DocumentRoot /var/www/html

    <Directory /var/www/html>
        Require all granted
    </Directory>

    # Enable rewrite engine
    RewriteEngine On

    # Capture the Authorization header and pass it as an environment variable
    RewriteCond %{HTTP:Authorization} ^(.*)
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%1]

    # Proxy settings
    <FilesMatch \.php$>
        SetHandler "proxy:unix:/var/run/php/php-fpm.sock|fcgi://localhost"
    </FilesMatch>
</VirtualHost>

```

phpinfo()で下記変数の有無を確認

**`$_SERVER['HTTP_AUTHORIZATION']`**

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2024 年 5 月 14 日午前 2:20 UTC](https://forum.ficusonline.com/t/topic/510/3 "2024-05-14T02:20:47Z")

</div>



---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2024 年 5 月 14 日午前 7:38 UTC](https://forum.ficusonline.com/t/topic/510/4 "2024-05-14T07:38:31Z")

</div>

## Final Modification to run the flexisip file transfer server

Note) File Transfer Server php codes designed with Apache(required apace http header variables), so need to access it directly, not via proxy(nginx) .

> ### 1. apache folder

- 1-1: Replace **apache** folder

- 1-2: Edit the below line in **`apache/extra/httpd-ssl.conf`** to meet with your condition

> ### 2. nginx folder

- 2-1: Change file name of **`ft.conf`** to deactivate it: like **`ft.conf.old`** , or delete it.

> ### 3. hft\_conf folder(new)

- 3-1: For security reason, make **`hft_conf`** folder  
and move **`hft_conf/flexisip-http-file-transfer-server.conf`** into this folder.

- 3-2: define the below lines in **`hft_conf/flexisip-http-file-transfer-server.conf`**

> ### 4. docker-compose.yml

Reconfirm the below sections

- 4-1: **nginx** `volumes` section

- 4-2: **apache** `port` and `volumes` section

- 4-3: **ubuntu-flexisip** `volumes` section

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2024 年 5 月 16 日午前 4:32 UTC](https://forum.ficusonline.com/t/topic/510/5 "2024-05-16T04:32:00Z")

</div>

### 参考）

#### Nginxでダイジェスト認証する場合の設定例

```auto
http {
    server {
        listen 80;

        location / {
            # バックエンドサーバーへのプロキシ設定
            proxy_pass http://backend_server;

            # 必要なヘッダーをバックエンドに渡す設定
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;

            # Authorizationヘッダーを渡す設定
            proxy_set_header Authorization $http_authorization;

            # 以下はオプションですが、一般的に使われるヘッダーの設定
            proxy_set_header Accept-Encoding "";
            proxy_set_header Connection "";
        }
    }
}

```

#### キャッシュを利用している場合

```auto
http {
    proxy_cache_path /path/to/cache levels=1:2 keys_zone=my_cache:10m max_size=10g inactive=60m use_temp_path=off;

    server {
        listen 80;

        location / {
            proxy_pass http://backend_server;

            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
            proxy_set_header Authorization $http_authorization;

            proxy_cache my_cache;
            proxy_cache_valid 200 302 10m;
            proxy_cache_valid 404 1m;

            # 認証ヘッダーが存在する場合にキャッシュをバイパス
            proxy_cache_bypass $http_authorization;
            # 認証ヘッダーが存在する場合にキャッシュからのレスポンスを無効化
            proxy_no_cache $http_authorization;
        }
    }
}

```

#### Apache ProxyPassMatchによるfcgiの実行例

```auto
<VirtualHost *:80>
    ServerName www.example.com

    # FastCGIプロキシの設定
    ProxyPassMatch ^/(.*\.php)$ fcgi://127.0.0.1:9000/path/to/webroot/$1

    # 必要なモジュールの読み込み
    LoadModule headers_module modules/mod_headers.so
    LoadModule cache_module modules/mod_cache.so
    LoadModule cache_disk_module modules/mod_cache_disk.so

    # キャッシュの設定
    CacheRoot "/path/to/cache"
    CacheEnable disk "/"
    CacheDirLevels 2
    CacheDirLength 1

    <Directory "/path/to/webroot">
        # 認証ヘッダーがある場合にキャッシュを無効にする設定
        SetEnvIf Authorization "(.*)" noauth
        Header set Cache-Control "no-store" env=noauth
        CacheDisable "noauth"
    </Directory>
</VirtualHost>

```

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2024 年 5 月 27 日午前 7:39 UTC](https://forum.ficusonline.com/t/topic/510/6 "2024-05-27T07:39:53Z")

</div>

## Conferenceサーバの設定

> **[2. Conference server - XWiki](https://wiki.linphone.org/xwiki/wiki/public/view/Flexisip/C.%20Features/Conference%20server/)**
>
> 2. Conference server

#### デバックモードで起動

**`docker compose`** ファイル内の`ubuntu-flexisip` の `cmd` オプションで **`"--server proxy"`** を指定して`proxy` のみを起動してから、コンテナ`ubuntu-flexisip` 内で下記サーバのいずれかを **`--debug`** オプションを指定して起動。各サーバの動作を確認。

```auto
# /opt/belledonne-communications/bin/flexisip --server conference --debug

```

> **[Conference server configuration - XWiki](https://wiki.linphone.org/xwiki/wiki/public/view/Flexisip/Configuration/Conference%20server%20configuration/)**
>
> Conference server configuration

‼ **注）** どちらのポート`(5065, 6064)` も外部（インターネット）に開放する必要はありません。

‼ **注）** `[conference-server], [b2bua-server]`の **outbound-proxy** のSIPアドレスを、`[global]`セクションの **transports** に必ず追加すること。

> [conference-server], [b2bua-server]  
> outbound-proxy=sip:127.0.0.1:7902;transport=tcp

> [global]  
> transports=sip:127.0.0.1:7902;transport=tcp …

```ini
[conference-server]

enabled=true

transport=sip:127.0.0.1:6064;transport=tcp

# For chat conference:conference-factory, For audio/video conference :videoconference-factory
conference-factory-uris=sip:videoconference-factory@example.com sip:conference-factory@example.com

conference-focus-uris=sip:dummy001@example.com sip:dummy002@example.com

outbound-proxy=sip:127.0.0.1:5060;transport=tcp

local-domains=sip.example.com example.com

database-backend=mysql

database-connection-string=db=xxxxxxx user=xxxxxxx password=xxxxxxxx host=xx.xx.xx.xx

# Whether the conference server shall check device capabilities
# before inviting them to a session.
# The capability check is currently limited to Linphone client that
# put a +org.linphone.specs contact parameter in order to indicate
# whether they support group chat and secured group chat.
# Default: true
check-capabilities=false

# List of media supported by the conference server.
# Valid values are: audio, video and text. For example:
# supported-media-types=audio video text
# Default: text
supported-media-types=audio video text

# The preferred encryption the conference server will offer in the
# outgoing transactions.
# Valid values are: none, sdes, zrtp and dtls.
# Default: none
encryption=none

# Whether the conference server will delete chat rooms that have
# no participants registered.
# 
# Default: true
empty-chat-room-deletion=true

# Directory where the conference server state files are stored.
# 
# Default: /var/opt/belledonne-communications/lib/flexisip
state-directory=/var/opt/belledonne-communications/lib/flexisip

```

> **注）** 一つのSIPドメインに対し、 **conference-factory-uris, conference-focus-uris** には、それぞれ2つのURIを指定していますが、Linphoneの設定で会議用URIとビデオ・オーディオ会議用URIを同一にすれば、2つ目のURIは削除できます。

> **[conference-server - XWiki](https://wiki.linphone.org/xwiki/wiki/public/view/Flexisip/A.%20Configuration%20Reference%20Guide/master/conference-server)**
>
> conference-server

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2024 年 5 月 30 日午後 10:42 UTC](https://forum.ficusonline.com/t/topic/510/7 "2024-05-30T22:42:58Z")

</div>

## 他ドメインとの相互運用

> **[Interoperability between two domains - XWiki](https://wiki.linphone.org/xwiki/wiki/public/view/Flexisip/HOWTOs/Interoperability%20between%20two%20domains/)**
>
> Interoperability between two domains

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2024 年 8 月 30 日午前 2:18 UTC](https://forum.ficusonline.com/t/topic/510/9 "2024-08-30T02:18:23Z")

</div>



---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2025 年 7 月 7 日午前 2:02 UTC](https://forum.ficusonline.com/t/topic/510/10 "2025-07-07T02:02:18Z")

</div>

## ファイル転送サーバ：トラブルシュート

### ダウンロードエラー

Ingress-NGINXなどのリバースプロキシでTLS終端を行うと、バックエンドのApacheサーバではリクエストがHTTPとして処理されます。これにより、PHPアプリケーションが生成するファイルのダウンロードURLが `http://` となり、LinphoneなどHTTPSを必須とするクライアントではダウンロード（401エラー）に失敗します。これは、クライアント側がHTTPSを要求している一方で、サーバがHTTP URLを返してしまうという不整合によって発生する問題です。

`hft.php`

修正前

```php
$prefix = (isset($_SERVER["HTTPS"]) && strtolower($_SERVER["HTTPS"]) == "on") ? "https" : "http";
$start = $prefix . "://" . $ipport . ':' . $_SERVER['SERVER_PORT'] . dirname($_SERVER['REQUEST_URI']);
$http_url = $start . "/tmp/" . basename($uploadfile); // file will be served in the ./tmp/ directory on the server path

```

修正案A：HTTPSでのみアクセスする場合

> `SERVER_PORT` → `HTTP_X_FORWARDED_PORT` へ変更

```auto
$prefix = (isset($_SERVER["HTTPS"]) && strtolower($_SERVER["HTTPS"]) == "on") ? "https" : "http";
$start = $prefix . "://" . $ipport . ':' . $_SERVER['HTTP_X_FORWARDED_PORT'] . dirname($_SERVER['REQUEST_URI']);
$http_url = $start . "/tmp/" . basename($uploadfile); // file will be served in the ./tmp/ directory on the server path

```

> 注）nginxの設定ファイルで明示的に以下を記述
> 
> - `proxy_set_header X-Forwarded-Proto https;`
> - `proxy_set_header X-Forwarded-Port 443;`
> - `proxy_set_header Authorization $http_authorization;`

> 注）Apacheの設定ファイルで以下を追加
> 
> ```auto
> <IfModule setenvif_module>
> SetEnvIf X-Forwarded-Proto "https" HTTPS=on
> # Set up the environment variable for the Authorization header
> SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1
> </IfModule>
> 
> ```

修正案B：HTTPまたはHTTPSでアクセスする場合

```php
$prefix = (isset($_SERVER["HTTPS"]) && strtolower($_SERVER["HTTPS"]) == "on" || isset($_SERVER["HTTP_X_FORWARDED_PROTO"]) && strtolower($_SERVER["HTTP_X_FORWARDED_PROTO"]) == "https") ? "https" : "http";
$serverport = $_SERVER['HTTP_X_FORWARDED_PORT'] ?? $_SERVER['SERVER_PORT'];
$start = $prefix . "://" . $ipport . ':' . $serverport . dirname($_SERVER['REQUEST_URI']);
$http_url = $start . "/tmp/" . basename($uploadfile); // file will be served in the ./tmp/ directory on the server path

```

> 注）HTTP\_\*\*\*などのヘッダー環境変数は`phpinfo()`で確認すること。

* * *

### サイズ制限

アップロードするファイルサイズはphp.iniとnginxの設定で決まります。

`/etc/nginx/default.conf`

```auto
client_max_body_size 100M;

```

`/usr/local/etc/php/php.ini`

```auto
upload_max_filesize = 50M
post_max_size = 100M

```

* * *

### Linphoneログアップロードエラー

ダイジェスト認証を有効にした場合、Linphoneでログのアップロードプロセスがエラーになります。Linphoneのログをアップロードする際には、ダイジェスト認証を無効にするか、ダイジェスト認証を有効にした場合は `hft.php` に下記コードを追加して対応します（この場合、直接ホストからダウンロード）。

`hft/hft-server/hft.php`

```php
function process_request() {
	if (
        $_SERVER['REQUEST_METHOD'] === 'POST' &&
        (int)($_SERVER['CONTENT_LENGTH'] ?? 0) === 0
    ) {
        fhft_log(LogLevel::DEBUG,
            "Empty POST detected, returning 204");

        http_response_code(204);
        exit();
    }

```

また、最新の登録アカウントによりログのアップロードが実行されるため、アカウントのドメインがファイルサーバのドメインと一致しない場合も認証エラーが発生します。
