Hi everyone !
Newcomer here, 1st time setting up Atlassian products, I've been deploying Core, Service Desk and Confluence successfully in my infrastructure. All are behind an "haproxy" reverse proxy, which handles SSL and redirects to the proper app based on the URL/hostname.
Tinkering with user management to centralize it via Jira Core, I soon though SSO would be a serious plus, so I've deployed Crowd. However, after following config instructions, I seem to be hitting a wall, can't get my setup to work.
I configured Crowd as a "User Directory" for Core/SD/Confluence (and added those apps in Crowd), gave access to various Crowd groups on Core/SD/Confluence and could successfully authenticate with a Crowd account on those (makes me think my base Crowd setup if functional).
However, when I change WEB-INF/classes/seraph-config.xml on Core/SD/Confluence server configs to set it to the SSO authenticator, login never succeeds and adds a captcha.
This shows up in catalina.out (from Jira Core) when a login is attempted:
08-Aug-2018 14:53:05.596 WARNING [http-nio-8080-exec-16] com.sun.jersey.spi.container.servlet.WebComponent.filterFormParameters A servlet request, to the URI https://<jira core url>/rest/gadget/1.0/login, contains form parameters in the request body but the request body has been consumed by the servlet or a servlet filter accessing the request parameters. Only resource methods using @FormParam will work as expected. Resource methods consuming the request body by other means will not work as expected.
As we mean to access the setup remotely and via hostnames, all configs, app and "User Directory" links have been done with hostnames, not private IPs. So the apps/servers talk to each other via the reverse proxy, and this has worked fine up till attempting to set up SSO.
When adding applications in Crowd, I used names with spaces (Jira Core, Jira SD, etc..), so I initially wondered if this would require quotes in crowd.properties, or if it simply would fail. To check, I added an app entry with "jiraconf" name, and changed crowd.properties accordingly for the Jira Core server. Didn't help, so I guess the issue isn't here.
I wonder if I have a "cookie" issue of some sort for SSO. Could the "https to http" transition done by the proxy be the problem ? After login attempts, I do see a "domain" cookie added in my browser.
Ideas ? Pointers ?
Additional details:
- Added IPs in "Trusted Proxy Servers"
- Added IPs and hostnames to Crowd apps "Remote Addresses"
- All hostnames resolve to the same public IP
- Linux/CentOS based setup with latest app versions
Observations:
- when logging off from the Crowd server, I need to manually delete its related browser cookies to successfully re-login. Otherwise I'm stuck to the login page