Inhaltsverzeichnis

Preparation of the Server I

Warning: This manual is no longer up to date!

FIXME!

Important: These recommendations are intended for people who install SoSci Survey on a virtual server (V-Server, VPS) or a root server. If you have only rented web space, you usually do not have to worry about the server settings.

SSL-Encrypted Data Transmission

If the data is transmitted unencrypted, it can be intercepted at many points on its way through the internet. A plausible scenario here would be the IT department taking a look at the responses in a company survey.

To solve this problem reliably, the data transmission can be encrypted by means of HTTPS or SSL. The data is then encrypted directly by the browser and only decrypted again on the server. An SSL certificate is available from 50 euros per year. You can also create certificates yourself, but as long as they are not certified, the browser displays a warning on every page.

Encrypted Access to the Server

To transfer data to the server, you will usually use an FTP program (e.g., FileZilla). For access to the database, maybe a convenient SQL frontend (e.g., HeidiSQL). However, if these are used without encryption, the passwords can be intercepted. Even if it probably happens rather rarely: The idea of criminals distributing spam or illegal content via your own server, or tapping data, is rather unpleasant.

If you can access the server encrypted via SSH, a lot of security can be achieved quickly: Simply select the encrypted variant SFTP instead of the transfer method FTP, and use PuTTY (which you probably use for shell access to the server anyway) to establish an encrypted SSH tunnel for MySQL. This also offers the security benefit that MySQL access can generally be restricted to the server (localhost), i.e., for example, a MySQL user admin@localhost instead of admin@%.

Detailed instructions (in German) for encrypted MySQL access are provided by Tsunamihost.

Security Updates

Web servers are only secure as long as they are up to date. If the hosting provider does not take care of the updates, you can conveniently do this yourself every few weeks. Log in to the shell via PuTTY, then enter the following commands:

apt-get update   (updates the software lists)
apt-get upgrade  (installs the updates)

Of course, there remains a residual risk that SoSci Survey might cause some problems on the new Apache or PHP version. But this risk is considerably lower than the danger posed by security holes in outdated software.

Anonymization of the Logfiles

Even if a project manager disables the recording of IP addresses, it is possible in principle to reconstruct the IP address from the time of the survey and the entry in the server logfile. The practical risk of identifying individual persons this way certainly exists under certain circumstances, especially in company surveys. Identifying individual internet users, in contrast, is rather a hypothetical risk.

Configuring the Mail Server Correctly

To prevent emails from the server from ending up in spam filters or being blocked entirely (“connection refused”), some settings are required on the mail server:

MySQL Configuration

To store the data (Data in SoSci Survey), SoSci Survey uses the database engine InnoDB in a MySQL database (MySQL: Overview of InnoDB tables). Among other things, this has the advantage that various consistency checks are already performed by the database, e.g., questions or responses cannot accidentally be stored for a deleted project.

However, there are some differences between the default engine MyISAM and InnoDB. These may require a separate configuration: