SSL ãŸã㯠HTTPS äžã§ã® Jira ã¢ããªã±ãŒã·ã§ã³ã®å®è¡
ã¢ãã©ã·ã¢ã³ ã¢ããªã±ãŒã·ã§ã³ã§ã¯ SSL ã䜿çšã§ããŸãããSSL ã®æ§æã¯ã¢ãã©ã·ã¢ã³ ãµããŒãã®å¯Ÿè±¡å€ã§ããããã§ããµããŒããšããŠæ¬¡ãå©çšããããšããå§ãããŸãã
- èšŒææžã®å€æã«éããŠãµããŒããå¿ èŠã§ããã°ãèšŒææžã®æäŸå ã®ã¢ãã©ã·ã¢ã³ ããŒãããŒã«çžè«ããŠãã ããã
- SSL ã®èšå®ã«é¢ããŠãµããŒããå¿ èŠãªå Žåã¯ãã¢ãã©ã·ã¢ã³ ã³ãã¥ããã£ã§è³ªåãäœæããŠãã ããã
æ¢ç¥ã®è匱æ§ã«ãã£ãŠ SHA-1 ã¯æ®µéçã«å»æ¢ãããŸãã
ãã®èšäºã§ã¯ãApache Tomcat ã§ HTTPS ãèšå®ããããšã§ Jira ã¢ããªã±ãŒã·ã§ã³ã SSL ãŸã㯠HTTPS äžã§å®è¡ããæ¹æ³ã説æããŸãããã®æé 㯠Jira ãéåžžã®æ¹æ³ã§ã€ã³ã¹ããŒã«ãããŠããå ŽåãåæãšããŠããŸããHTTPS èšå®ã®ãã¹ãŠãç¶²çŸ ããæé ã®èª¬æã§ã¯ãªãããããå©çšã®ç°å¢ã«ã¯é©çšãããªãå ŽåããããŸãã
ãã®ããŒãã®è©³çްã¯ã次ã®èšäºããåç §ãã ããã
Jira ã SSL ãŸã㯠HTTPS äžã§å®è¡ããå¿ èŠãããçç±ãŠãŒã¶ãŒãã€ã³ã¿ãŒããããçµç±ã㊠Web ã¢ããªã«ã¢ã¯ã»ã¹ãããšããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒãšäŒæ¥ã® ISP (ã€ã³ã¿ãŒããã ãµãŒãã¹ ãããã€ããŒ) éã®äžç¶ç¹ã§ãŠãŒã¶ãŒåããã¹ã¯ãŒããååãããå¯èœæ§ãåžžã«ãããŸãããã®ãããHTTPS (HTTP over SSL) çµç±ã§ã®ã¢ã¯ã»ã¹ãæå¹ã«ããŠããã¹ã¯ãŒããéä¿¡ããããŒãžã§ãããå¿ é ã«ããããšãæšå¥šãããŸãããã ããHTTPS ã䜿çšãããšããã©ãŒãã³ã¹ãäœäžããå¯èœæ§ãããããšã«ã泚æãã ããã
HTTPS ã䜿çšããã« Jira ãå®è¡ãããšãã€ã³ã¹ã¿ã³ã¹ãäžéè æ»æãDNS ãªãã€ã³ãã£ã³ã°æ»æãªã©ã«æãããå¯èœæ§ããããŸããã€ã³ã¹ã¿ã³ã¹ã§ã¯ HTTPS ãæå¹åããããšããå§ãããŸãã
ã¯ãããåã«
ãµããŒã
ã¢ãã©ã·ã¢ã³ã®ãµããŒãã¯ãSSL ã®ãµããŒãã«ã€ããŠã¯èšŒææžãçºè¡ããèªèšŒå± (CA) ã«å§ããŸãããã®ããŒãžã«ããã SSL é¢é£ã®èª¬æã¯åèæ å ±ãšããŠã®ã¿æäŸãããŸãã
Windows ã€ã³ã¹ããŒã©ãŒ
Windows ã€ã³ã¹ããŒã©ãŒã¯ãTomcat ãå®è¡ããããã«ç¬èªã® JRE (Java ã©ã³ã¿ã€ã ç°å¢) Java ãã©ãããã©ãŒã ãã€ã³ã¹ããŒã«ããŸããSSL èšŒææžã®ã¢ããããŒãæã¯ãJRE ã®ã€ã³ã¹ããŒã«ããéã«å®è¡ããŠãã ããã
é¢é£ãã°
Jira 7.3 以éã¯ãserver.xml ãã¡ã€ã«ã®ãããã³ã«ã誀ã£ãŠèšå®ãããã° 2 ã€ã®åœ±é¿ãåããŸãããããã³ã«ãæåã§èšå®ããããšã§ãã®èª²é¡ãåé¿ã§ããŸãã
ãªããŒã¹ãããã·ã®èåŸã«ãã Jira
Jira ã Apache ã®ãããªãªããŒã¹ãããã·ã®èåŸã«ãã¹ããããŠããå Žåã®è©³çްã«ã€ããŠã¯ãSSL ã«ãã£ãŠ Jira ãš Apache ãçµ±åãããããåç §ãã ããã
æ°ããæ¥ç¶ã®è¿œå
SSL ãªã©ã®æ°ããæ¥ç¶ã远å ããéã«ãJira èšå®ããŒã«ã¯æ¥ç¶ã®è©³çްãå«ããšã³ããªã server.xml ãã¡ã€ã«ã«ä¿åããŸãããã®ãšã³ããªã¯ç¹æ®æåãåŠçããããããã£ãå«ãŸãªããããæåã§è¿œå ããå¿
èŠããããŸãããã®ããããã£ããªããã° Jira ã¯é©åã«æ©èœããªããããããã¯å¿
é ã®æäœã§ãã以éã§å¿
èŠãªæé ã説æããŸãã詳现ã«ã€ããŠã¯ãã¡ããã芧ãã ããã
å®å šæ§ãäœã BKS-V1 ããŒã¹ãã¢åœ¢åŒ
BouncyCastle ã©ã€ãã©ãªã§æäŸããã BKS-V1 ããŒã¹ãã¢åœ¢åŒã«ã¯ã»ãã¥ãªãã£ã®è匱æ§ãããããããå©çšã® Jira ã€ã³ã¹ã¿ã³ã¹ã§ã¯äœ¿çšããªãããšããå§ãããŸãã詳现æ å ±
Java ããŒã¹ãã¢ã®çæ
ã客æ§ã® SSL èšŒææžãä¿åãã Java ããŒã¹ã㢠(JKS) ãäœæããæ¹æ³ã«ã€ããŠèª¬æããŸããSSL èšŒææžã¯ãJira ã§ SSL éä¿¡ãè¡ãããã«ã¯å¿ é ã®ãã®ã§ããSSL èšŒææžã¯äžè¬çã«æ¬¡ã® 2 ã€ã®çš®é¡ã«åºåãããŸãã
| èšŒææž | 説æ | 䜿çšç°å¢ | æé |
|---|---|---|---|
| èªå·±çœ²åèšŒææž | èªèšŒå±ã«ããããžã¿ã«çœ²åããªãèšŒææžã§ããWeb ãµãŒããŒèšŒææžã®æ£åœæ§ã確èªããæ¹æ³ã§ããèªåèªèº«ãèªå·±åã§çœ²åããŸãã | ãã¹ãçšãéçºçšããã®ä»å éšåããµãŒããŒã®ã¿ | 1-13 |
| CA 眲åèšŒææž | èªèšŒå± (CA) ã®ããžã¿ã«çœ²åã«ãã£ãŠæ£åœæ§ã確èªãããèšŒææžã§ããããã«ããããã©ãŠã¶ãã¯ã©ã€ã¢ã³ãã¯èšŒææžã«ä¿¡çšã眮ãããšãå¯èœã«ãªããŸãã | æ¬çªç°å¢çšãµãŒã㌠| 1-19 |
ä¿¡çšã®ããããµãŒãããŒãã£ãŒèªèšŒå± (CA) ãçºè¡ããããžã¿ã«èšŒææžã«ãããã客æ§ã® Web ãµã€ããã客æ§ã®äŒç€Ÿãæ£åœã«ä»£è¡šãããã®ã§ããããšã蚌æãããã客æ§ã®äŒç€Ÿã®å®åšãèªèšŒãããŸããå€ãã® CA ã§ã¯åã«ãã¡ã€ã³åã®ã¿ãèªèšŒããèšŒææžãçºè¡ããŸãããVeriSign ãªã©ã§ã¯ãã客æ§ã®äºæ¥æŽ»åã®ååšããã¡ã€ã³åã®æææš©ã®ååšãèšŒææžäœ¿çšã«é¢ããã客æ§ã®æš©éãªã©ã蚌æããé«åºŠã®èªèšŒãæäŸããŠããŸãã
CA ã®äžèЧã¯ããããã芧ãã ãããããç¥ãããèªèšŒå±ã®äŸã次ã«ç€ºããŸã:
åœç€ŸãšããŠã¯ãCA ã§çœ²åãããèšŒææžã®å©çšãæšå¥šããããŸãã
Portecle ãã客æ§ã®ãµãŒããŒã«ã€ã³ã¹ããŒã«ã§ããªãããŸãã¯ã³ãã³ã ã©ã€ã³ã®å©çšããåžæã®å Žåã¯ã以äžã®ãã³ãã³ã ã©ã€ã³ã«ããã€ã³ã¹ããŒã«ãã»ã¯ã·ã§ã³ããåç §ãã ããã
Portecle ã¢ããªãããŠã³ããŒãããŠãJira ãå®è¡ãããµãŒããŒã«ã€ã³ã¹ããŒã«ããŸãã
 ãã®ã¢ããªã±ãŒã·ã§ã³ã¯ãµãŒãããŒãã£ãŒè£œã§ãããã¢ãã©ã·ã¢ã³ã§ã¯ãµããŒã察象å€ã§ãã
é©åãªæš©éãæã£ãŠå®è¡ã§ããããã«ãã¢ããªã管çè ãšããŠå®è¡ããŸãããŸãã
<JAVA_HOME>倿°ã Jira ã§äœ¿çšãã Java ãšåãããŒãžã§ã³ã瀺ããŠããããšã確èªããŸãã詳现ã«ã€ããŠã¯ããJAVA_HOME ã®èšå®ããåç §ããŠãã ãããLinux/Unix ãµãŒããŒäžã§å®è¡ããŠããå Žåã¯ã以äžã®ããã«ãµãŒããŒã«æ¥ç¶ããéã« X11 ã転éããããšã§ GUI ãå©çšã§ããŸããÂ
ssh -X user@server- [Create a new Keystore] ãéžæããŸãã
- [JKS] 圢åŒãéžæã㊠[OK] ãã¯ãªãã¯ããŸãã
- [Generate Key Pair] ãéžæããŸãã
- [Key Algorithm] ã§ã¯ [RSA] ãã[Key Size] ã§ã¯ [2048] ãéžæããŸãã
- [Signature Algorithm] ã [SHA256withRSA] ãšãªã£ãŠããããšã確èªããŸãããæ¢å®ã® SSL æå·åã匱ãããããšã«ã€ããŠã®ã»ãã¥ãªã㣠ããŒã«ããã®å ±åãããåç
§ãã ããã
 以äžã®äŸã®ããã«èšŒææžã®è©³çްãç·šéã㊠[OK] ãéžæããŸãã
[Common Name] ã¯ãµãŒããŒã® URL ãšäžèŽããŠããå¿ èŠããããŸããäžèŽããªãå Žåã¯ãšã©ãŒããã©ãŠã¶ã«è¡šç€ºãããŸãã
- èšŒææžã®ãšã€ãªã¢ã¹åãéžæããŸããäŸ:
jira - ããŒã¹ãã¢ã®ãã¹ã¯ãŒããå
¥åããŸããæ¢å®ã®ãã¹ã¯ãŒãã¯éåžž
changeitã§ãã - ã㌠ãã¢ã®çæãæåããæšã®ã¡ãã»ãŒãžã衚瀺ãããŸãã
åã®ã¹ããããšåããã¹ã¯ãŒãã䜿çšãããŠããããšã確èªããŠãããŒã¹ãã¢ã
<Jira_HOME>/jira.jksã«ä¿åããŸãã[ãã¡ã€ã«] > [ããŒã¹ãã¢ã®ä¿å] ãéžæããŠä¿åã§ããŸããèªå·±çœ²åèšŒææžã䜿çšããå Žåã¯ããJira èšå®ããŒã«ãå©çšãã Web ãµãŒããŒã®èšå®ãã«é²ãã§ãã ããããã以å€ã®å Žåã¯æ¬¡ã®æé ã«é²ã¿ãŸãã
- èšŒææžã®æ£åœæ§ã確èªããããã«èªèšŒå±ã«å¯ŸããŠçœ²åãäŸé ŒããèšŒææžçœ²åèŠæ± (CSR) ãçæããå¿
èŠããããŸãããããè¡ãããã«ã¯ãèšŒææžäžã§å³ã¯ãªãã¯ããŠ[CSR ã®çæ] ãéžæããŸããCSR ãã¡ã€ã«ã
<Jira_HOME>/jira.csrã«ä¿åããŸãã - CSR ã眲åã®ããã«èªèšŒå±ã«éä¿¡ããŸããèªèšŒå±ããã¯ãçœ²åæžã¿èšŒææž (CA å¿ç) ããã³ CA ã®ã«ãŒãèšŒææž/äžéèšŒææžã®ã»ãããè¿éãããŸãã
- [Import Trusted Certificate] ã§ã«ãŒãèšŒææžãšäžéèšŒææžã®äž¡æ¹ (ãããã¯çæ¹) ãã€ã³ããŒãããŸããèšŒææžããšã«ãã®æé ãç¹°ãè¿ããŸãã
jiraèšŒææžã§å³ã¯ãªãã¯ã㊠[Import CA Reply] ãéžæãã眲åä»ãèšŒææžã®ã€ã³ããŒããéå§ããŸãã- èªèšŒå±ããæäŸãããèšŒææž (
jira.crt) ãéžæããŸããCA å¿çã®ã€ã³ããŒããå®äºãããšããéç¥ãå±ããŸãã - çµæã [ããŒã«] > [ããŒã¹ã㢠ã¬ããŒã] ã§ç¢ºèªããŸããèšŒææžã¯ã«ãŒãèšŒææžã®åããŒããšããŠè¡šç€ºãããŸãã
- ããŒã¹ãã¢ãä¿åããæ¬¡ã®ã»ã¯ã·ã§ã³ã«é²ã¿ãŸã :
Jira èšå®ããŒã«ãå©çšãã web ãµãŒããŒã®èšå®
Jira ã§ã® SSL æå·åèšå®ã®æåŸã®æé ãšããŠãJira èšå®ããŒã«ãå©çšã㊠Web ãµãŒããŒãèšå®ããŸããJira èšå®ããŒã«ã®è©³çްã¯ããJira èšå®ããŒã«ã®å©çšããã芧ãã ããã
- 次ã®ããã« Jira èšå®ããŒã«ãå®è¡ããŸãã
- Windows: ã³ãã³ã ããã³ãããéããŠãJira ã€ã³ã¹ããŒã« ãã£ã¬ã¯ããªã®
binãµããã£ã¬ã¯ããªã«ããconfig.batãå®è¡ããŸãã Linux/Unix: ã³ã³ãœãŒã«ãéããŠãJira ã€ã³ã¹ããŒã« ãã£ã¬ã¯ããªã®
binãµããã£ã¬ã¯ããªã«ããconfig.shãå®è¡ããŸãããã®ã³ãã³ãã¯ãNo X11 DISPLAY 倿°ãåå ã§ Jira ã¢ããªã±ãŒã·ã§ã³èšå®ããŒã«ãèµ·åã§ããªãã£ãã®ã¯ãèšå®ãšã©ãŒã«ãããã®ãã«èšèŒã®ãšã©ãŒã§å€±æããå ŽåããããŸãããã®å Žåã¯ããã®èšäºã®åé¿çããåç §ãã ããã
- Windows: ã³ãã³ã ããã³ãããéããŠãJira ã€ã³ã¹ããŒã« ãã£ã¬ã¯ããªã®
- [Web ãµãŒããŒ] ãéžæããŸãã
ã¹ã¯ãªãŒã³ã·ã§ãã: Jira èšå®ããŒã« â [Web ãµãŒããŒ] ã¿ã åãã£ãŒã«ãã«æ¬¡ã®ããã«å ¥åããŸã :
ãã£ãŒã«ã å€ ããŒãã®å¶åŸ¡ éåžžã¯åæèšå®ã®ãŸãŸãšããŸããå¿ èŠã«å¿ããŠããŒãçªå·ã倿Žããããšãã§ããŸãã詳现ã¯ãJira ã® TCP ããŒãã®å€æŽããã芧ãã ããã ãããã£ãŒã« ãããã¡ã€ã«ãšã¯ããªã»ããããã Web ãµãŒããŒåäœèšå®ã§ããæ¬¡ã® 4 ã€ã®å€ããéžæã§ããŸãã - ç¡å¹
- HTTP ã®ã¿Â
- HTTP ããã³ HTTPS (HTTP ã HTTPS ãžãªãã€ã¬ã¯ã)
- HTTPS ã®ã¿
Jira ã HTTPS äžã§å®è¡ããå Žåã¯ã[HTTP & HTTPS] ãŸã㯠[HTTPS] ãéžæããå¿ èŠããããŸãã
Jira ã HTTPS äžã§å®è¡ãããããŠãŒã¶ãŒã HTTP çµç±ã§ã Jira ã¢ã¯ã»ã¹ã§ããããã«ããå Žåã¯ã[HTTP & HTTPS] ãéžæããŠãã ããããã®å ŽåãHTTP çµç±ã§ Jira ã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã¯ HTTPS ã®ã¢ãã¬ã¹ã«ãªãã€ã¬ã¯ããããŸãã
HTTP ããŒã éåžžã¯åæèšå®ã®
8080ã®ãŸãŸã«ããŸããå¿ èŠã«å¿ããŠããŒãçªå·ã倿Žããããšãã§ããŸãã詳现ã¯ãJira ã® TCP ããŒãã®å€æŽããã芧ãã ããã[ãããã¡ã€ã«] ã§ [HTTPS ã®ã¿] ãéžæããå Žåã¯ãã®ãã£ãŒã«ãã¯ç¡å¹ã«ãªããŸãã
HTTPS ããŒã éåžžã¯åæèšå®ã® 8443ã®ãŸãŸã«ããŸããå¿ èŠã«å¿ããŠããŒãçªå·ã倿Žããããšãã§ããŸãã詳现ã¯ãJira ã® TCP ããŒãã®å€æŽããã芧ãã ãããKeystore ãã¹ èšŒææžã®ããŒã¹ãã¢ã®å Žæãæå®ããŸããããã¯ãããŒã¹ãã¢ãä¿åããéã«çæãããå Žæã§ã
<Jira_HOME>/jira.jksã§ããKeystore ãã¹ã¯ãŒã ããŒã¹ãã¢ã®ãã¹ã¯ãŒããæå®ããŸããèªå·±çœ²åèšŒææžãçæããå Žåã¯ããã®ãã¹ã¯ãŒãã¯èšŒææžãçæããŠä¿åãããšãã«ããŒããã³ããŒã¹ãã¢ã«èšå®ãããã¹ã¯ãŒãã§ãã Keystore ãšã€ãªã¢ã¹ ããŒã¹ãã¢å ã®ããããã®é ç®ã¯ãšã€ãªã¢ã¹ã§åºå¥ãããŸããèšŒææžã«ã€ã㊠jiraã䜿çšããããšãæšå¥šããŸãã- ç¡å¹
- [Check Certificate in Key Store (ããŒã¹ãã¢ã®èšŒææžããã§ãã¯ãã)] ãéžæããŠã次ã®é
ç®ã確èªããŸãã
- ããŒã¹ãã¢å ã«èšŒææžãååšããããšã
- ããŒã¹ãã¢ã®ãã¹ã¯ãŒããæå¹ã§ããããšã
- ã㌠ãšã€ãªã¢ã¹ã䜿çšããŠããŒãèŠã€ããããããšã
- 倿Žãä¿åããŸãã
æ°ããæ¥ç¶ã®è¿œå æã«ãèšå®ããŒã«ã«ã¯ç¹æ®æåãèš±å¯ããããããã£ãå«ãŸããªãããããããã server.xml ãã¡ã€ã«ã«æåã§è¿œå ããå¿
èŠããããŸããæ¹æ³ã®è©³çްã«ã€ããŠã¯ãã¡ãã®èšäºããåç
§ãã ããã
é«åºŠãªèšå®
åäžãã¹ãã«ãããè€æ°ã®ã€ã³ã¹ã¿ã³ã¹ã®å®è¡
åäžãã¹ãã§è€æ°ã®ã€ã³ã¹ã¿ã³ã¹ãå®è¡ããå Žåã¯ãaddress 屿§ã <Jira_INSTALLATION>/conf/server.xml ãã¡ã€ã«ã§æå®ããŸããæ¢å®ã§ã¯ã³ãã¯ã¿ã¯å©çšå¯èœãªãã¹ãŠã®ãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹äžã§ãªãã¹ã³ããŠãããåäžã®æ¢å®ããŒãäžã§å®è¡ãããã³ãã¯ã¿éã®è¡çªã鲿¢ããããã«ã¢ãã¬ã¹ãæå®ããå¿
èŠãããããã§ããaddress 屿§ã®èšå®ã®è©³çްã«ã€ããŠã¯ãApache Tomcat ããã¥ã¡ã³ãã®ãThe HTTP Connectorããã確èªãã ããã
ã³ãã³ã ã©ã€ã³ã䜿çšããã€ã³ã¹ããŒã«
ã¹ããã 1.ããŒã¹ãã¢ãäœæããŸã
Java ããŒã¹ãã¢ãçæããŸãã
<JAVA_HOME>/keytool -genkey -alias jira -keyalg RSA -keystore <Jira_HOME>/jira.jkså§å (first and last names) ã®éšåã«ã¯ããµãŒããŒã® URL ãããhttps://ããé€ãããã® (jira.atlassian.com ãªã©) ãæå®ããŸãã
- ãã¹ã¯ãŒããå ¥åããŸãã
æé 2 ã®ãã¹ã¯ãŒãã䜿çšããŠã眲åã®ããã® CSR ãçæããŸãã
<JAVA_HOME>/keytool -certreq -alias jira -file /output/directory/csr.txt -keystore <Jira_HOME>/jira.jksCSR ã眲åã®ããã«èªèšŒå±ã«éä¿¡ããŸããèªèšŒå±ããã¯ãçœ²åæžã¿èšŒææžãš CA ã®ã«ãŒãèšŒææžãŸãã¯äžéèšŒææžãè¿éãããŸãã
èšŒææžã眲åãããŠããªãå Žåã¯ããKeystore ã§ Tomcat ãæŽæ°ããããŸã§ã¹ãããããŸãã
ã«ãŒãèšŒææžããŸãã¯äžéèšŒææžãã€ã³ããŒãããŸãã
<JAVA_HOME>/keytool -import -alias rootCA -keystore <Jira_HOME>/jira.jks -trustcacerts -file root.crtèªèšŒå±ããè¿éãããçœ²åæžã¿èšŒææžãã€ã³ããŒãããŸãã
<JAVA_HOME>/keytool -import -alias jira -keystore <Jira_HOME>/jira.jks -file jira.crtããŒã¹ãã¢å ã«èšŒææžãååšããããšã確èªããŸãã
<JAVA_HOME>/keytool -list -alias jira -keystore <Jira_HOME>/jira.jksããã¯
PrivateKeyEntryã§ããå¿ èŠããããŸããç°ãªãå ŽåãèšŒææžã®ã»ããã¢ãããæ£åžžã«å®äºããŠããŸãããæ¬¡ã«äŸã瀺ããŸããjira, Jan 1, 1970, PrivateKeyEntry, Certificate fingerprint (MD5): 73:68:CF:90:A8:1D:90:5B:CE:2A:2F:29:21:C6:B8:25
ã¹ããã 2.Keystore ã§ Tomcat ãæŽæ°ãã
- ç·šéããåã«ã
<Jira_INSTALL>/conf/server.xmlã®ããã¯ã¢ãããäœæããŸãã HTTPS ã³ãã¯ã¿ãç·šéããããŒã¹ãã¢ã瀺ããã©ã¡ãŒã¿ãŒãå«ããŸãã
<Connector relaxedPathChars="[]|" relaxedQueryChars="[]|{}^\`"<>" port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxHttpHeaderSize="8192" SSLEnabled="true" maxThreads="150" minSpareThreads="25" enableLookups="false" disableUploadTimeout="true" acceptCount="100" scheme="https" secure="true" sslEnabledProtocols="TLSv1.2,TLSv1.3" clientAuth="false" useBodyEncodingForURI="true" keyAlias="jira" keystoreFile="<Jira_HOME>/jira.jks" keystorePass="changeit" keystoreType="JKS"/>é©åãªãã¹ã
<Jira_HOME>ã«å ¥åããŠãå¿ èŠã«å¿ããŠããŒãã倿ŽããŸããçµç¹ãææ°ã® TLS ããŒãžã§ã³ããµããŒãããŠããªãå Žåã¯ã以åã®ããŒãžã§ã³ãžãã©ãŒã«ããã¯ã§ããŸããæ¬¡ã®ããã«å€æŽããŸãã
sslEnabledProtocols="TLSv1.2,TLSv1.3"to
sslEnabledProtocols="TLSv1,TLSv1.1,TLSv1.2,TLSv1.3"HTTP ã³ãã¯ã¿ãç·šéããHTTPS ã³ãã¯ã¿ãžãªãã€ã¬ã¯ãããããã«ããŸããÂ
<Connector relaxedPathChars="[]|" relaxedQueryChars="[]|{}^\`"<>" acceptCount="100" connectionTimeout="20000" disableUploadTimeout="true" enableLookups="false" maxHttpHeaderSize="8192" maxThreads="150" minSpareThreads="25" port="8080" protocol="HTTP/1.1" redirectPort="<PORT_FROM_STEP_1>" useBodyEncodingForURI="true"/><PORT_FROM_STEP_1>ãé©åãªå€ã«å€æŽãããŠããããšã確èªããŸãããã®äŸã§ã¯8443ã§ãã- 倿ŽãÂ
server.xmlã«ä¿åããŸãã HTTPS ãžã®ãªãã€ã¬ã¯ãã䜿çšããå Žå (æšå¥š)ã
Jira_INSTALL>/WEB-INF/web.xmlãã¡ã€ã«ãç·šéãããã¡ã€ã«ã®æ«å°Ÿã«æ¬¡ã®ã»ã¯ã·ã§ã³ã远å ããŠããã</web-app>ãéããŸãããã®äŸã§ã¯ãæ·»ä»ãã¡ã€ã«ãé€ããã¹ãŠã® URL ã HTTP ãã HTTPS ã«ãªãã€ã¬ã¯ããããŸãã<security-constraint> <web-resource-collection> <web-resource-name>all-except-attachments</web-resource-name> <url-pattern>*.jsp</url-pattern> <url-pattern>*.jspa</url-pattern> <url-pattern>/browse/*</url-pattern> <url-pattern>/issues/*</url-pattern> </web-resource-collection> <user-data-constraint> <transport-guarantee>CONFIDENTIAL</transport-guarantee> </user-data-constraint> </security-constraint>- 倿Žå 容ãä¿åã㊠Jira ãåèµ·åããŸãã
ãŸããJira èšå®ããŒã«ã§ãHTTP ãš HTTPSããããã¡ã€ã«ãéžæããŠãHTTP URL ãã HTTPS URL ãžãŠãŒã¶ãŒããªãã€ã¬ã¯ãããããšãã§ããŸããÂ
ç¹å®ã®ããŒãžã®ã¿ã HTTPS ãžãªãã€ã¬ã¯ããããå Žåã¯æåã§è¡ãå¿ èŠããããŸãã
- Jira èšå®ããŒã«ã§ãHTTPS ã®ã¿ããããã¡ã€ã«ãéžæããŠèšå®ãä¿åããŸãã
- HTTP URL ã察å¿ãã HTTPS URL ã«ãªãã€ã¬ã¯ããã Web ãµãŒããŒäžã«
htaccessãã¡ã€ã«ãäœæããŸãã
ãã©ãã«ã·ã¥ãŒãã£ã³ã°
äžèšã«ããéã Portecle ãçšããŠçæããèªå·±çœ²åããŒã䜿çšããå Žåã®ããã©ãã«ã·ã¥ãŒãã£ã³ã°ã® TIPS ãããã€ã玹ä»ããŸãã
ãã©ãŠã¶ã«ãhttps://localhost:<port number>ããšå
¥åãããšãã«ãCannot establish a connection to the server at localhost:8443ãã®ãããªã¡ãã»ãŒãžã衚瀺ãããå Žåã¯ãlogs/catalina.out ãã° ãã¡ã€ã«ã§ãšã©ãŒ ã¡ãã»ãŒãžãæ¢ããŸããããã§ã¯çºçããå¯èœæ§ãããããã€ãã®ãšã©ãŒãšããããã®èª¬æã玹ä»ããŸãã
ãã®å 容ã¯ã圹ã«ç«ã¡ãŸããã?
ã¯ã ãã®èšäºã«ã€ããŠã®ãã£ãŒãããã¯ãéä¿¡ãã








