Hello,
I have some questions and problems.1) How can I configure my help desk system without port eg. Call 8080 or 7070 I have tried it but it does not work.2) A technician has been trying for 7 days to connect the system help desk with an SSL certificate which can be called up with https.It is not but I have received the feedback that it was not possible and that you would have to do it because it is much too complex and you would have to reprogram the whole system.Could they do that for mcioh or say how it works and what I have to reprogram everything?Jirra is a bit flawed when it comes to SSl and I need your help.Thank you!
LG
For the port, you either have to run it behind a proxy, or run the Tomcat on port 443 (that's for https, you'd want 80 if it's going to be http). I recommend a proxy and SSL in most cases.
"It does not work" doesn't tell us what you have tried.
Jira is not at all hard to run over SSL, but you need to get the proxy or Tomcat working on a different port first.
I've tried all the tutorials on the internet using jirra with keystore.There was no correct manual that was simple and working I've programmed half the system but it just does not work.
I have also tried to let Jira run on port 443 and then point to the jira directory but that does not work.
"does not work" tells us nothing.
The fact is it does work (there's a fully SSL enabled Jira running in a tab right next to this one), but you've got something wrong.
The instructions are, I'd agree, not incredibly simple, but SSL itself is not simple.
The question becomes what are you doing differently to the standard docs, not "it doesn't work". Because the docs do describe how to make it work.
I tried it 50x and did everything according to the instructions but it does not work that also says my friend the hat tried it too.Also had a good guide.
You don't tell us what you tried, or what guide you have used, or what you have done differently to the guides.
We can't help you with this without you telling us what you're doing differently. I could easily write a full guide, but there's no point, because it would be mostly a copy of the documentation.
I did everything again according to instructions I reach Jirra over the port 8080 and over a new proxy port aver if I try it over https the error comes ERR_CONNECTION_CLOSED.
Ok, that's something we can work with. The error usually means that the proxy is misconfigured and refusing to talk to your browser. In some cases, it might be trying to talk to the browser, but being told by your Jira's Tomcat that it should not.
Could you confirm that Jira was ok when running on http://<a.server>:8080 though? No ssl, just the plain server and port? If this is true, it means we can focus on where the error really is with the proxy and its connection back to Jira.
Yes I can reach Jira perfectly without SSL under 7070 and 8080.I added that in the server.xml ...
<!-- Apache Proxy Connector with values for scheme, proxyName and proxyPort --><Connector acceptCount="100" connectionTimeout="20000" disableUploadTimeout="true" enableLookups="false" maxHttpHeaderSize="8192" maxThreads="150" minSpareThreads="25" port="8443" protocol="HTTP/1.1" redirectPort="8443" useBodyEncodingForURI="true"scheme="https" proxyName="system.meinedomain.com" proxyPort="443"/>
8843 is fail 8080 is ok.
If it helps you out, here is our nginx config for JIRA:
server {listen 80;server_name issues.example.com issues;return 301 https://issues.example.com$request_uri;
}
server {listen 443 ssl http2 default_server;server_name issues.example.com;
client_max_body_size 40M;large_client_header_buffers 4 4k;
#include conf.d/ssl.inc;
ssl on;ssl_protocols TLSv1 TLSv1.1 TLSv1.2;ssl_ciphers "ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4";ssl_prefer_server_ciphers on;ssl_session_cache shared:SSL:10m;
ssl_certificate /etc/pki/tls/certs/wildcard-example.com/wildcard.example.com.crt;ssl_certificate_key /etc/pki/tls/certs/wildcard-example.com/wildcard.example.com.key;ssl_session_timeout 5m;
location / {proxy_pass http://127.0.0.1:8080/;proxy_http_version 1.1;proxy_set_header Host $host;proxy_set_header X-Forwarded-Proto https;proxy_set_header X-Forwarded-For $remote_addr;}}
I work with Apache2 and I want to include a SSL / Https and not reprogram the whole system.
One issue I ran into when setting up SSL was after applying the cert via config.sh, SSL would not work, regardless of using port 8443 or 443. I stumbled across this https://jira.atlassian.com/browse/JRASERVER-63734?src=confmacro. Essentially the config.sh never updated the connector in the .xml correctly. After adding org.apache.coyote.http11.Http11Nioprotocol to the xml file and restarting services I was able to hit the site via ssl.
It was all right with me but I tried everything 1000x even my technician did not get it in 8 hours.
Use port forwarding in iptables and configure tomcat to use your ssl keystore. I have jira running this way and also using an mysql over ssl as well.
Great dose of patience here, kudos
I dont believe free nginx supports SAML
It looks like you're new here. Sign in or register to get started.