I have internal URLs for Jira http://xxx.xxx.xxx.xxx:8080 and Confluence http://xxx.xxx.xxx.xxx:8090 and I want to make the URL's public. However, I do not want to make them anonymous, so I am using an ssl cert with current permissions. Is there anythin specific that I need to do to accomplish moving the URl's to public access? I have all the DNS issues resolved, I just need to know if there are any permissions that need to be changes and how to load the SSL Cert into Jira itself.
Thanks,
Mark
Hi Mark,
The best practice for exposing your URLs publicly and implementing SSL for them is to use a reverse proxy in front of the Atlassian applications. NGINX and Apache are free, here are the docs:
Integrating JIRA with Nginx
Running Confluence behind NGINX with SSL
Securing your Atlassian applications with Apache using SSL
To allow the public to access your URLs you will need to open a port on your firewall for SSL - port 443. The proxy will direct requests that are going to https://DNS_NAME over to http://xxx.xxx.xxx.xxx:8080 so the users won't have to type in the port number.
Ann
Hi Ann,
in this instance we are not using our NGINX firewall and we have Jira in use internally. We have Jira installed on Windows 2012 R2 running internally. what we want to do is have our external user have the ability too log on externally so that we do not have to provide an SSL VPN so that they can log in internally. The server is not running any web services and will just be Natted externally with port forwarding. If I install the SSL cert into the JRE directory will this suffice for our users to log on extarnally?
You have to add the certs to a keystore and define the location of the keystore in the server.xml file for each app. If Confluence and Jira will be connecting to one another for user management or application links and you are using a self signed cert, the certificate for each app will need to be added to the Java trust store of the other app.
Our docs say it better than I do:
Running Confluence Over SSL or HTTPS
Running JIRA applications over SSL or HTTPS
Thanks Ann. It is making sense and I am having difficulty with using the Java Keytool. My question now is if I make the modifications<confluence-install-directory>/conf/server.xml prior to the firewall cutover, will there be any affect on the internal URL's which everyone is using on a daily basis while we make it public. In other words, will this effort in making Jira public affect in any way the current production instance used on a daily basis. Also, the documentation seems to be for Confluence, would Jira follow the same instructions? Is there support available to assist us in doing this change to public?
Best Regards,
It looks like you're new here. Sign in or register to get started.