We have a server on which we're running Bitbucket. What I'd like to do is to allow plain http from the intranet (a 10.x.y.z network) and require https (on port 7980) from the outside (we have another system which simply forwards port 7980 to our Bitbucket server). The default http-over-port-7990 Just Works(tm), but I'm not getting SSL working.
What I've done is to create a key in a keystore using the keytool, and then I added a Connector:
<Connector port="7980" protocol="org.apache.coyote.http11.Http11NioProtocol"
maxHttpHeaderSize="8192"
maxThreads="150" SSLEnabled="true" scheme="https" secure="true"
enableLookups="false"
disableUploadtimeout="true"
useBodyEncodingForURI="true"
acceptCount="100"
clientAuth="false" sslProtocol="TLS"
keyAlias="tomcat"
keystoreFile="/etc/bitbucket.jks"
keystorePass="xxx"
keystoreType="JKS" />After restarting bitbucket, according to netstat -anl, I can see that it's binding the port. When I try to connect to the server, Firefox keeps trying to get a response. curl says this:
$ curl -vvvvvvvvvvvvvvvv https://xxx:7980
[---]
* CAfile: none
[---]
* TLSv1.2 (OUT), TLS header, Certificate Status (22):
* TLSv1.2 (OUT), TLS handshake, Client hello (1):
^C
It just hangs after the client hello.
What should I be looking closer at? What am I missing?