# How to Configure TLS/SSL with Nginx Reverse Proxy for Production Deployment in MobileAudit

> Secure your MobileAudit production deployment by configuring TLS/SSL with Nginx reverse proxy. Follow our guide to generate certificates and set up secure HTTPS in minutes.

- Repository: [Mónica Pastor/mobileaudit](https://github.com/mpast/mobileaudit)
- Tags: how-to-guide
- Published: 2026-03-07

---

**To configure TLS/SSL for MobileAudit production deployment, generate SSL certificates in the `nginx/ssl/` directory, mount them via [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml), and use the pre-configured [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf) to terminate TLS at the Nginx reverse proxy while forwarding plain HTTP traffic to the Django web service on internal port 8000.**

MobileAudit is a Django-based security testing framework that requires HTTPS encryption for production environments. According to the mpast/mobileaudit repository source code, the project provides a production-ready Nginx configuration that handles TLS termination and reverse proxies requests to the backend application. This guide explains the exact file paths, Docker Compose mappings, and security configurations required to enable TLS/SSL for secure production deployment.

## Step 1: Generate TLS Certificates

MobileAudit expects SSL certificates in the `nginx/ssl/` directory at the project root. Create this directory if it does not exist, then generate a self-signed certificate for testing or place CA-signed certificates here for production use.

Execute the following OpenSSL command to create a 4096-bit RSA self-signed certificate valid for 365 days:

```bash
openssl req -x509 -nodes -days 365 \
  -newkey rsa:4096 \
  -subj "/C=ES/ST=Madrid/L=Madrid/O=Example/OU=IT/CN=localhost" \
  -keyout nginx/ssl/nginx.key \
  -out nginx/ssl/nginx.crt

```

For production environments using trusted certificates, replace `nginx.crt` and `nginx.key` with your CA-signed or Let's Encrypt certificate files, ensuring the filenames match the paths referenced in [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf).

## Step 2: Configure Nginx TLS Termination

The repository provides [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf), which contains the complete Nginx reverse proxy configuration with TLS support. This file defines an upstream server pointing to the Django application and enforces modern TLS protocols and security headers.

Key directives implemented in [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf) include:

- **Upstream definition**: The `upstream app` block resolves to `web:8000`, targeting the Django service within the Docker internal network.
- **TLS protocols**: `ssl_protocols TLSv1.2 TLSv1.3` ensures only secure protocol versions are accepted, excluding older vulnerable versions.
- **Certificate configuration**: `ssl_certificate` and `ssl_certificate_key` point to `/etc/nginx/ssl/nginx.crt` and `/etc/nginx/ssl/nginx.key` respectively.
- **Security headers**: Includes `Strict-Transport-Security "max-age=63072000; includeSubdomains"` to enforce HSTS.
- **Proxy settings**: The `location /` block forwards all traffic to `http://app/` with 500-second timeouts for connect, read, and send operations.
- **Static file serving**: Directories `/static/` and `/media/` are served directly via `alias` directives pointing to `/app/app/static/` and `/app/app/media/`, offloading the Django application.

## Step 3: Wire the Configuration into Docker Compose

The [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml) file orchestrates the production stack, mounting the TLS configuration and certificates into the Nginx container while keeping the Django application internal.

In [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml), the service definitions configure the following:

```yaml
services:
  web:
    build: .
    env_file: ./.env.example
    expose:
      - "8000"

  nginx:
    image: nginx:stable-bullseye
    ports:
      - "443:443"
    volumes:
      - ./nginx/app_tls.conf:/etc/nginx/conf.d/app_tls.conf
      - ./nginx/ssl:/etc/nginx/ssl
      - ./nginx/logs:/var/log/nginx
    depends_on:
      - web

```

This configuration exposes only port **443** to the host, while the `web` service remains internal on port 8000. The volume mounts ensure Nginx accesses the TLS configuration at [`/etc/nginx/conf.d/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main//etc/nginx/conf.d/app_tls.conf) and certificates at `/etc/nginx/ssl/`.

## Step 4: Start the Production Stack

With certificates in place and configurations verified, launch the production environment using the production-specific Docker Compose file:

```bash
docker-compose -f docker-compose.prod.yaml up -d

```

This command starts the Django application, PostgreSQL database, RabbitMQ message queue, Celery workers, and Nginx reverse proxy with TLS termination enabled. The `depends_on` directive ensures the `web` service initializes before Nginx attempts to proxy connections.

## Architecture Overview

MobileAudit's production architecture terminates TLS at the Nginx layer, keeping internal traffic unencrypted between the reverse proxy and Django application. The traffic flow follows this pattern:

1. **Client requests** arrive at `https://<host>:443` with TLS encryption
2. **Nginx** validates certificates, applies security headers, and decrypts the traffic
3. **Proxy pass** forwards plain HTTP to `http://app/` (resolving to `web:8000`)
4. **Django** processes the request and returns the response through the reverse proxy
5. **Static and media files** are served directly by Nginx without hitting the Django application

## Summary

Configuring TLS/SSL for MobileAudit production deployment requires coordinating three key components from the mpast/mobileaudit repository:

- **Place certificates** in `nginx/ssl/` as `nginx.crt` and `nginx.key` (or update paths in [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf))
- **Use [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf)** to enforce TLSv1.2/TLSv1.3 protocols, strong cipher suites, and HSTS headers at the reverse proxy
- **Deploy via [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml)** to mount configurations and expose only port 443 publicly, keeping the Django application on internal port 8000

This setup ensures encrypted client connections while allowing the Django web service to operate over plain HTTP internally, following the security model implemented in the source code.

## Frequently Asked Questions

### Where should SSL certificate files be stored in the MobileAudit project?

Store the `nginx.crt` and `nginx.key` files in the `nginx/ssl/` directory at the project root. The [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml) volume mapping `./nginx/ssl:/etc/nginx/ssl` mounts this directory to `/etc/nginx/ssl/` inside the Nginx container, allowing the [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf) configuration to reference them at `/etc/nginx/ssl/nginx.crt` and `/etc/nginx/ssl/nginx.key`.

### Can I use Let's Encrypt or other CA-signed certificates instead of self-signed ones?

Yes, simply replace the self-signed files in `nginx/ssl/` with your CA-signed certificate and private key, maintaining the filenames `nginx.crt` and `nginx.key`. If you use different filenames, update the `ssl_certificate` and `ssl_certificate_key` directives in [`nginx/app_tls.conf`](https://github.com/mpast/mobileaudit/blob/main/nginx/app_tls.conf) to match your certificate file paths.

### Which ports need to be exposed for secure production deployment?

Only **port 443** needs to be exposed publicly for HTTPS traffic, as configured in [`docker-compose.prod.yaml`](https://github.com/mpast/mobileaudit/blob/main/docker-compose.prod.yaml) under the `nginx` service ports mapping `"443:443"`. The Django `web` service uses port 8000 internally but should not be exposed directly to the host; Nginx handles all external traffic and proxies it to the application container.

### How do I verify that the TLS configuration is working correctly?

After running `docker-compose -f docker-compose.prod.yaml up -d`, test the deployment by accessing `https://localhost/` (or your domain) in a browser, or use `curl -k https://localhost/` to bypass certificate warnings for self-signed certs. Verify that the dashboard loads over HTTPS and that the certificate details match the files placed in `nginx/ssl/`.