Our company have JIRA, Confluence and Fisheye. All applications are located in intranet. Users cannot access outside office.
It seems to me it is not necessary to apply for a SSL cert and install.
The only problem I can see is, when user using Confluence to open an office document (e.g. word, excel) it prompt for "Access to this web server is disabled by default because it is controlled by basic authentication and does not use SSL....". This problem can be resolved by change registry (https://confluence.atlassian.com/confkb/unable-to-edit-files-in-office-due-to-ssl-not-being-enabled-598213057.html)
What do you think? I understand https should give better security. However, from an admin's view, is it worth the trouble?