Hi
I am setting up Jira DataCenter with SSL certificate and internal AD together with an Azure AD App Proxy via this plugin : https://www.microsoft.com/en-us/download/details.aspx?id=56506
Internal URL : https://jira-test.local:8443/jiraExternal URL : https://jira-mytenant.msappproxy.net
Followed this tutorial https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/jiramicrosoft-tutorial
When we now enter via the external URL, we see that SSO login works, but it switches from jira-mytenant.msappproxy.net to jira-test.local:8443/jira
I couldn't figure out yet why the URL does not remain the external one.
By the way the BaseURL (in Jira Gui) and the proxyname (in server.xml) have been set to https://jira-test.local:8443/jira and jira-test.local
I assume that the Azure proxy would keep the external address translated correctly.
Anyone that did a similar setup already and got this working ?
Thanks
Johan
It's not Azure Proxy that changes the URL, but Jira - it issues a redirect to the baseURL.
This is default behaviour by design in the configuration you've described (baseURL in UI and proxyname in server.xml)
I think the only way to make it work is to make both internal and external URL the same, and then overwrite the external name in your internal DNS.
Thanks for your help.
When I change the baseURL and the proxyname into the external one's, I get a warning (+ login screen with the Azure Login button)
"Dashboard Diagnostics: Mismatched URL Hostname"
If I just use user + password it continues using the external url correctly (until I reach some jira pages, where it changes again into the internal one)
If I try the login button instead, then I get following error : "InResponseTo of the response does not match the ID of the authentication request. Please try again."
Any idea if this also comes from Jira or might be a configuration issue in Azure AD ?
By setting the proxyname in the server.xml file on the different connectors towards the external address, the warning is gone.
The issue is now only for SSO part.
It gives me either this "Invalid response. Empty Destination value. Please contact your Azure AD admin" when I go in via the microsoft app portal or the "Inresponse..." error if I go via the msappproxy URL and clicking the button.
So the bottomline is "something is misconfigured"
1) Why do you even have multiple connectors in server.xml? Is proxy accessing Jira via one and direct users via another? Are these on different ports? What is doing SSL for each? IMO you should only have one connector, on port 443 (unless you also have one on port 80 purely for convenience, that immediately redirects everything to 443)and Jira must have one true name (baseURL). Consider emails being sent by Jira - either you are inside the network or outside (from home) clicking on the link should send you to exactly the same URL.
2) Re: SAML errors - when you configured SAML originally you most likely had to tell Azure the URL where you application is i.e. the SP's Assertion Consumer Service (ACS) URL, aka the SAML endpoint. You also normally specify the Entity ID. These may have been provided automatically via metadata.xml file. Most of the SAML apps construct these URLs automatically based on the baseURL. If your baseURL has changed (it's not all external right?) - you probably need to re-do the integration.
It looks like you're new here. Sign in or register to get started.