I have a JIRA setup that uses an Apache reverse proxy (AJP protocol) front end with SSL server certificate. The reverse proxy just means that the SSL connection ends at Apache and Apache then forwards it to a special AJP connector in JIRA that listens on JIRA's port on localhost. This has worked just fine for 10 years.
My agency now requires that users must use client certificates in the form of a Common Access Card (CAC) as used by the government and military to see the server in addition to the normal SSL connection. No real problem there, either, since Apache has simple configuration file entries to require incoming connections to first present a client certificate signed by our agency.
That all works smoothly because the client certificate requirement is just to gain access to the server login screen to which they must login with their regular login credentials. I don't have to grok the users' credentials from the certificate or anything. It just needs to be valid and correctly signed.
After requiring client certificates there was an initial glitch with Application Links (Confluence is on the same physical server on a separate tomcat server). Application Links have always worked fine over SSL because the server SSL certificate was explicitly in the Java truststore. But the client certificate requirement munged Application Links communication via the Base URL so I just created a separate localhost-only http connector for both JIRA and Confluence to communicate with each other and that also works fine after configuring the remote application URL to be, for example, http://localhost:8090/confluence to connect to Confluence instead of the normal Base URL. That is an acceptable workaround.
The problem is with JIRA's change in how gadgets get rendered from 7.1 on. The client certificate requirement manifests the JIRA gadget title bug wherein titles appear like this: _MSG_gadget.activity, _MSG_gadget.filter, _MSG_gadget.project.title
See Health Check: JIRA Base URL and How to fix gadget titles showing as __MSG_gadget
There is no immediate workaround that I can find because JIRA is hard-coded to use the Base URL (its external address) for accessing itself as explained in the link. I can't redirect it to localhost as with the Application Links to bypass Apache and its client certificate requirement. If I turn off the client certificate requirement in Apache then things work fine and the gadgets render correctly. So, basically Apache is rejecting JIRA's connection to itself because it presents no client certificate.
I am wondering if anyone has any suggestions on what I might look at to work around the title rendering problem. It is not show-stopping serious from a functional standpoint but it does look pretty shabby. I am going to look at iptables to see if there is a way to take any packets coming from the server to the server and redirect them to localhost instead. I haven't found any examples out there of that exactly so I will need to study up on iptables.