I want to set up two layers of password protection on the public facing version of our Jira server. The normal Jira login, and an Apache login.
I've tried various different methods and nothing's worked. The issue seems to be that when I use apache login (virtual host, proxypass to ajp connector, with auth on the proxy element) jira tries to use those credentials which fails with this error in the atlassian-jira-security.log
2013-08-22 16:38:36,161 ajp-bio-8009-exec-4 anonymous 998x427x1 1k0mhp6 10.1.11.112 /secure/MyJiraHome.jspa login : 'mark.james' tried to login but they do not have USE permission or weren't found. Deleting remember me cookie.
If i add a user to apache auth with the same username and password as a jira account it works ok (but then there's only 1 level of login.)
i've tried setting tomcatAuthentication="true" on the connector but it made no diff (true is the default value anyway.)
any suggestions/help much appreciated,
mark