Web Server

Field: Security

A web server is software, or the process running it, that accepts requests over HTTP or HTTPS from a user agent such as a web browser and returns the requested content, or an error message if the request cannot be fulfilled.

RFC 9110 defines an HTTP server as “a program that accepts connections in order to service HTTP requests by sending HTTP responses.” A web server can return a file as stored, known as static content, or pass the request to a program that generates the response, known as dynamic content. The Common Gateway Interface (CGI) is an early standard for that handoff (RFC 3875), and the program on the receiving end is often a web application. The term names the software, but it is also commonly used for the computer that runs it.

Web servers range from general-purpose servers such as nginx and the Apache HTTP Server (packaged as apache2 on Debian and Ubuntu) to application servers that run a web application’s code directly, such as Apache Tomcat for Java and Puma and WEBrick for Ruby. In many deployments the two are layered, with a general-purpose server in front acting as a reverse proxy, which RFC 9110 also calls a gateway, handling connections and static files and passing dynamic requests to an application server behind it. A load balancer is a special case of a reverse proxy that spreads requests across several servers, and it often terminates TLS, the encryption that protects the confidentiality and integrity of traffic in transit, so that connections are decrypted at the load balancer rather than at each server behind it.

Sources

See also