Hello,
I need my confluence website to go through ports 80 and 443. I am using Ubuntu 12.04 as the server and read that only privileged users are able to use ports below 1024. I am not going to give the confluence user root privileges and I found several people saying that you can use an apache mod_proxy to accomplish this. None of the instructions I found are very descriptive and I could use some assistance.
Hi Daryl,
In this case you will need a webserver as a proxy.
To use this with apache for example, you just need to set a virtual host with mod_proxy enabled like this:
<VirtualHost *:443>
#Creating virtual host
ServerAdmin admin@domain.com
ServerName confluence.example.com
ServerAlias confluence.example.com
#enabling SSL (If you have a certificate)
SSLEngine On
SSLCertificateFile /path/to/file.crt
SSLCertificateKeyFile /path/to/file.key
ProxyRequests Off
ProxyPreserveHost On
<Proxy *>
Order deny,allow
Allow from all
</Proxy>
ProxyPass / http://your_confluence_original_url:8085/
ProxyPassReverse / http://your_confluence_original_url:8085/
<Location />
Order allow,deny
</Location>
ErrorLog /path/to/example.com-error.log
LogLevel debug
CustomLog /path/to/example.com-access.log combined
</VirtualHost>
Regards.
I think I set this up correctly, but the URL displayed ends up showing http:\\website:8080, which will not work due to our restrictive firewall settings. Is there a way to have all external traffice go through 80?
hi daryl.
did you added a vhost like the example Celso posted?
<Proxy *> Order deny,allow Allow from all </Proxy> ProxyPass / http://your_confluence_original_url:8085/ ProxyPassReverse / http://your_confluence_original_url:8085/
this is the important part that will make it happen.
if you've configured it correctly your confluence will not respond if you enter "http://Your_website:8080" in your browser..if it still does something in your set up must be incorrect.
this is how it could look like (this works 100%)
please note i used ajp connector to seperate things here better
<VirtualHost YOUR_URL_HERE:443> ErrorLog /var/log/httpd/YOU_NAME_IT/error_log TransferLog /var/log/httpd/YOU_NAME_IT/access_log #SSL Section SSLEngine on SSLProtocol all -SSLv2 SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM SSLCertificateFile /path/to/some/CRT SSLCertificateKeyFile /path/to/some/KEY SetEnvIf User-Agent ".*MSIE.*" nokeepalive ssl-unclean-shutdown CustomLog /var/log/httpd/YOU_NAME_IT/ssl_request_log \ "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b" # /SSL Section ServerAdmin admin@somewhere ServerName YOUR_SERVER ServerAlias YOUR_SERVER ProxyRequests Off ProxyPreserveHost On <Proxy *> Order deny,allow Allow from all </Proxy> SSLProxyEngine On ProxyRequests Off ProxyPreserveHost On ProxyPass / ajp://localhost:${confluence_PORT}/ ProxyPassReverse / ajp://localhost:${confluence_PORT}/ <Location /> Order allow,deny Allow from all </Location> </VirtualHost>
When I try this, apache doesn't even start. The error logs don't log anything either.
The original answer is working, just not the way I'd like. Using port 80, it redirects to 8080, which then redirects to 8443, but the URL changes to https://website:8443, which I can't use externally.
what does apache log show?
there must be a reason it is not starting...
ErrorLog /var/log/httpd/YOU_NAME_IT/error_log
TransferLog /var/log/httpd/YOU_NAME_IT/access_log
#ErrorLog /var/log/httpd/YOU_NAME_IT/error_log #TransferLog /var/log/httpd/YOU_NAME_IT/access_log #CustomLog /var/log/httpd/YOU_NAME_IT/ssl_request_log \ "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
ProxyPass / http://localhost:${confluence_PORT}/ ProxyPassReverse / http://localhost:${confluence_PORT}/
hmm i got no idea whats in this file...for your confluence vhost i'd suggest creating a new conf file in the same folder where your 000-default is located.
but as you say celsos posting works for you but redirects to 8443...the setting must be somewhere else...
did you changed anything in
<CONFLUENCE_INSTALLATION>/confluence/WEB-INF/web.xml ?
you can see here
https://confluence.atlassian.com/display/DOC/Running+Confluence+Over+SSL+or+HTTPS#RunningConfluenceOverSSLorHTTPS-Step5.AddaSecurityConstrainttoCauseRedirectofAllURLstoHTTPS
that is what comes in my mind right now.
if you would like to we can go through it step by step..
I don't think I'm doing this right at all. My knowledge of linux is fairly amateur. Do I leave the 000-default virtual host file alone? Or do I add all this to that file?
This is a self signed cert I made using some instructions I found
<VirtualHost *:443> #Creating virtual host ServerAdmin admin@domain.com ServerName wiki.sylint.com ServerAlias wiki.sylint.com SSLEngine on SSLCertificateFile /etc/apache2/ssl/apache.crt SSLCertificateKeyFile /etc/apache2/ssl/apache.key ProxyRequests Off ProxyPreserveHost On <Proxy *> Order deny,allow Allow from all </Proxy> ProxyPass / http://localhost:8080/ ProxyPassReverse / http://localhost:8080/ <Location /> Order allow,deny Allow from all </Location> ErrorLog /logs/error.log LogLevel debug CustomLog /logs/access.log combined </VirtualHost>
Please google this error. There are several hints availabe on this wich i really don't wanna post here to avoid blowing up this thread
It looks like I got this working. Thanks for your help.
It looks like you're new here. Sign in or register to get started.