Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Jira Apache ssl error

Marcin Beczynski
Contributor
June 13, 2018

Hello

I have tried configure jira with apache and ssl but fail with error what is not descibed at any instruction

Server.xml Conector :
<Connector acceptCount="100"
connectionTimeout="20000"
disableUploadTimeout="true"
enableLookups="false"
maxHttpHeaderSize="8192"
maxThreads="150"
minSpareThreads="25" port="8080"
protocol="HTTP/1.1"
redirectPort="8443"
useBodyEncodingForURI="true"
scheme="https"
proxyName="jira.example.com"
proxyPort="443"/>

 

apache.config:


<VirtualHost jira.example.com:80>
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule (.*) https://%{HTTP_HOST}%{REQUEST_URI}
</VirtualHost>
<VirtualHost jira.example.com:443>
ServerName www.jira.example.com
ServerAlias jira.example.com
DocumentRoot /opt/atlassian/jira
ErrorLog /var/log/httpd/jira_error.log
CustomLog /var/log/httpd/jira_requests.log combined
# otherwise act as a proxy to jira which is running on port 8080
<Proxy *>
Order deny,allow
Allow from all
</Proxy>
ProxyRequests Off
ProxyPreserveHost on
SSLProxyEngine On
SSLEngine on
ProxyPass / http://jira.example.com:8080/
ProxyPassReverse / http://jira.example.com:8080/
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/jira.example.com/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/jira.example.com/privkey.pem
SSLCertificateChainFile /etc/letsencrypt/live/jira.example.com/chain.pem
</VirtualHost>

 


ssl.conf:

Listen 443 https
SSLPassPhraseDialog exec:/usr/libexec/httpd-ssl-pass-dialog
SSLSessionCache shmcb:/run/httpd/sslcache(512000)
SSLSessionCacheTimeout 300
SSLRandomSeed startup file:/dev/urandom 256
SSLRandomSeed connect builtin
SSLCryptoDevice builtin
<VirtualHost _default_:443>
DocumentRoot "/var/www/jira.example.com"
ServerName www.jira.example.com:443
ErrorLog logs/ssl_error_log
TransferLog logs/ssl_access_log
LogLevel warn
SSLEngine on
<Files ~ "\.(cgi|shtml|phtml|php3?)$">
SSLOptions +StdEnvVars
</Files>
<Directory "/var/www/cgi-bin">
SSLOptions +StdEnvVars
</Directory>
BrowserMatch "MSIE [2-5]" nokeepalive ssl-unclean-shutdown downgrade-1.0 force-response-1.0
CustomLog logs/ssl_request_log "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
ServerAlias www.jira.example.com
SSLCertificateFile /etc/letsencrypt/live/jira.example.com/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/jira.example.com/privkey.pem
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateChainFile /etc/letsencrypt/live/jira.example.com/chain.pem
</VirtualHost>
SSLCipherSuite EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH
SSLProtocol All -SSLv2 -SSLv3
SSLHonorCipherOrder On
Header always set Strict-Transport-Security "max-age=63072000; includeSubdomains"
Header always set X-Frame-Options DENY
Header always set X-Content-Type-Options nosniff
SSLCompression off
SSLUseStapling on
SSLStaplingCache "shmcb:logs/stapling-cache(150000)"

1 answer

0 votes
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 13, 2018

Hi Ivan,

From looking at your configuration options, the only concern I have to understand what specific address you are trying to use to access this Jira site:

www.jira.example.com or  jira.example.com ?  

I see there is a serveralias there, but my concern is to understand what URL the end user uses here.  It is possible that the Tomcat configuration in Jira  would need to be tweaked to understand this slightly different URL is being used for the site instead or just jira.example.com

 

Can you share with us more details about the specific error you are getting here?

  1. Is the redirect just not working, or is it much worse that Jira won't start up?
  2. What version of Jira is this?
  3. What version of Apache are you using?
  4. Do you see an error when trying to load the Jira site via this proxied connector?

Are you following an existing KB guide?   Could you let me know which one you're using?  I would recommend Securing your Atlassian applications with Apache using SSL

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events