Hi Community,
we are running our Confluence behind an apache https proxy on a Debian9 Server. Confluence is the only app running on that machine.
However Collaborate stops working and can not reach its backend.
In the apache logs i can see following entries:
[proxy:error] [pid 7851] (111)Connection refused: AH00957: HTTP: attempt to connect to 127.0.0.1:8091 (localhost) failed
Port 8091 is up and running, but somehow the websocketconnect fails miserably.
Here is our Apache Config for the proxy:
ApacheConfig SSL for Confluence
#### confluence section
<VirtualHost *:443>
TimeOut 1000
ServerName confluence.our.site
DirectoryIndex index.html
SSLEngine on
#Certificates
SSLCertificateFile /etc/apache2/ssl/our.site.crt
SSLCertificateChainFile /etc/apache2/ssl/AlphaSSL_Intermediate_CA.pem
SSLCertificateKeyFile /etc/apache2/ssl/our.site.key
SSLCACertificateFile /etc/apache2/ssl/GlobalSign_Root_R1_CA.pem
SSLProxyEngine on
RewriteEngine on
ProxyRequests off
ProxyPreserveHost on
RequestHeader set X-Forwarded-Proto "https"
RequestHeader set X-Forwarded-Port "443"
LogLevel info ssl:debug
ErrorLog ${APACHE_LOG_DIR}/our.site-ssl-error.log
CustomLog ${APACHE_LOG_DIR}/our.site-ssl-access.log combined
<Proxy *>
Require all granted
</Proxy>
ProxyPass /synchrony http://localhost:8091/synchrony
<Location /synchrony>
Require all granted
RewriteEngine on
RewriteCond %{HTTP:UPGRADE} ^WebSocket$ [NC]
RewriteCond %{HTTP:CONNECTION} Upgrade$ [NC]
RewriteRule .* ws://localhost:8091%{REQUEST_URI} [P]
</Location>
ProxyPass / http://localhost:8090/
ProxyPassReverse / http://localhost:8090/
<Directory "/var/www/our.site">
Options +FollowSymLinks +SymLinksIfOwnerMatch
AllowOverride All
Require all granted
</Directory>
#Certbot
ProxyPass /.well-known !
ProxyPassReverse /.well-known !
#additional ssl
SSLProtocol all -SSLv2 -SSLv3
SSLHonorCipherOrder on
SSLCompression off
</VirtualHost>
###end of confluence section
#### balsamiq rtc section
Listen our.site:9083
<VirtualHost *:9083>
SSLEngine on
#Certificates
SSLCertificateFile /etc/apache2/ssl/our.site.crt
SSLCertificateChainFile /etc/apache2/ssl/AlphaSSL_Intermediate_CA.pem
SSLCertificateKeyFile /etc/apache2/ssl/our.site.key
SSLCACertificateFile /etc/apache2/ssl/GlobalSign_Root_R1_CA.pem
ProxyRequests off
ProxyPreserveHost On
RewriteEngine on
<Proxy *>
Require all granted
</Proxy>
ProxyPass / http://localhost:9083/
RewriteEngine on
RewriteCond %{HTTP:UPGRADE} ^WebSocket$ [NC]
RewriteCond %{HTTP:CONNECTION} Upgrade$ [NC]
RewriteRule .* ws://localhost:9083%{REQUEST_URI} [P]
</VirtualHost>
###end of balsamiq rtc section
We also have a port 80 vhost which redirects to the https:
<VirtualHost *:80>
TimeOut 1000
UseCanonicalName On
ServerAdmin root@localhost
ServerName confluence.our.site
DocumentRoot "/var/www/our.site"
DirectoryIndex index.html
ProxyRequests Off
LogLevel info
ErrorLog ${APACHE_LOG_DIR}/our.site-prod-error.log
CustomLog ${APACHE_LOG_DIR}/our.site-access.log combined
<Directory "/var/www/our.site">
AllowOverride All
Options +FollowSymLinks +SymLinksIfOwnerMatch
Require all granted
</Directory>
RewriteEngine on
#RewriteCond %{THE_REQUEST} !/.well-known/acme-challenge/ [NC]
RewriteCond %{SERVER_NAME} =confluence.solar-log.com
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
our confluence server.xml:
<Server port="8000" shutdown="SHUTDOWN" debug="0">
<Service name="Tomcat-Standalone">
<Connector port="8090" connectionTimeout="20000" redirectPort="8443"
address="127.0.0.1"
maxThreads="48" minSpareThreads="10"
enableLookups="false" acceptCount="10" debug="0" URIEncoding="UTF-8"
protocol="org.apache.coyote.http11.Http11NioProtocol"
scheme="https" secure="true" proxyName="confluence.our.site" proxyPort="443"/>
<Engine name="Standalone" defaultHost="localhost" debug="0">
<Host name="localhost" debug="0" appBase="webapps" unpackWARs="true" autoDeploy="false" startStopThreads="4">
<Context path="" docBase="../confluence" debug="0" reloadable="false" useHttpOnly="true">
<!-- Logging configuration for Confluence is specified in confluence/WEB-INF/classes/log4j.properties -->
<Manager pathname=""/>
<Valve className="org.apache.catalina.valves.StuckThreadDetectionValve" threshold="60"/>
</Context>
<Context path="${confluence.context.path}/synchrony-proxy" docBase="../synchrony-proxy" debug="0"
reloadable="false" useHttpOnly="true">
<Valve className="org.apache.catalina.valves.StuckThreadDetectionValve" threshold="60"/>
</Context>
</Host>
</Engine>
</Service>
</Server>
We are unable to open the ws sockets - this is also for balsamiq which also does not work.
In order to use confluence we had to stop collaborate completely. But this is not what we wish. We need collaborate working.
We have no running firewall on that server, but we have security tools rkhunter, aide, auditd, acct and lynis working.
Can please someone help?
Greetings,
Tux