SSL ãŸã㯠HTTPS äžã§ã® Jira ã¢ããªã±ãŒã·ã§ã³ã®å®è¡
ã¢ãã©ã·ã¢ã³ ã¢ããªã±ãŒã·ã§ã³ã§ã¯ SSL ã䜿çšã§ããŸãããSSL ã®æ§æã¯ã¢ãã©ã·ã¢ã³ ãµããŒãã®å¯Ÿè±¡å€ã§ããããã§ããµããŒããšããŠæ¬¡ãå©çšããããšããå§ãããŸãã
- 蚌ææžã®å€æã«éããŠãµããŒããå¿ èŠã§ããã°ã蚌ææžã®æäŸå ã®ã¢ãã©ã·ã¢ã³ ããŒãããŒã«çžè«ããŠãã ããã
- SSL ã®èšå®ã«é¢ããŠãµããŒããå¿ èŠãªå Žåã¯ãã¢ãã©ã·ã¢ã³ ã³ãã¥ããã£ã§è³ªåãäœæããŠãã ããã
æ¢ç¥ã®è匱æ§ã«ãã£ãŠ SHA-1 ã¯æ®µéçã«å»æ¢ãããŸãã
ãã®èšäºã§ã¯ãApache Tomcat 㧠HTTPS ãèšå®ããããšã§ Jira ã¢ããªã±ãŒã·ã§ã³ã SSL ãŸã㯠HTTPS äžã§å®è¡ããæ¹æ³ã説æããŸãããã®æé 㯠Jira ãéåžžã®æ¹æ³ã§ã€ã³ã¹ããŒã«ãããŠããå ŽåãåæãšããŠããŸããHTTPS èšå®ã®ãã¹ãŠãç¶²çŸ ããæé ã®èª¬æã§ã¯ãªãããããå©çšã®ç°å¢ã«ã¯é©çšãããªãå ŽåããããŸãã
ãã®ããŒãã®è©³çŽ°ã¯ã次ã®èšäºããåç §ãã ããã
Jira ã SSL ãŸã㯠HTTPS äžã§å®è¡ããå¿ èŠãããçç±ãŠãŒã¶ãŒãã€ã³ã¿ãŒããããçµç±ã㊠Web ã¢ããªã«ã¢ã¯ã»ã¹ãããšããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒãšäŒæ¥ã® ISP (ã€ã³ã¿ãŒããã ãµãŒãã¹ ãããã€ããŒ) éã®äžç¶ç¹ã§ãŠãŒã¶ãŒåããã¹ã¯ãŒããååãããå¯èœæ§ãåžžã«ãããŸãããã®ãããHTTPS (HTTP over SSL) çµç±ã§ã®ã¢ã¯ã»ã¹ãæå¹ã«ããŠããã¹ã¯ãŒããéä¿¡ããããŒãžã§ãããå¿ é ã«ããããšãæšå¥šãããŸãããã ããHTTPS ã䜿çšãããšããã©ãŒãã³ã¹ãäœäžããå¯èœæ§ãããããšã«ã泚æãã ããã
HTTPS ã䜿çšããã« Jira ãå®è¡ãããšãã€ã³ã¹ã¿ã³ã¹ãäžéè æ»æãDNS ãªãã€ã³ãã£ã³ã°æ»æãªã©ã«æãããå¯èœæ§ããããŸããã€ã³ã¹ã¿ã³ã¹ã§ã¯ HTTPS ãæå¹åããããšããå§ãããŸãã
ã¯ãããåã«
ãµããŒã
ã¢ãã©ã·ã¢ã³ã®ãµããŒãã¯ãSSL ã®ãµããŒãã«ã€ããŠã¯èšŒææžãçºè¡ããèªèšŒå± (CA) ã«å§ããŸãããã®ããŒãžã«ããã SSL é¢é£ã®èª¬æã¯åèæ å ±ãšããŠã®ã¿æäŸãããŸãã
Windows ã€ã³ã¹ããŒã©ãŒ
Windows ã€ã³ã¹ããŒã©ãŒã¯ãTomcat ãå®è¡ããããã«ç¬èªã® JRE (Java ã©ã³ã¿ã€ã ç°å¢) Java ãã©ãããã©ãŒã ãã€ã³ã¹ããŒã«ããŸããSSL 蚌ææžã®ã¢ããããŒãæã¯ãJRE ã®ã€ã³ã¹ããŒã«ããéã«å®è¡ããŠãã ããã
é¢é£ãã°
Jira 7.3 以éã¯ãserver.xml
ãã¡ã€ã«ã®ãããã³ã«ã誀ã£ãŠèšå®ãããã° 2 ã€ã®åœ±é¿ãåããŸãããããã³ã«ãæåã§èšå®ããããšã§ãã®èª²é¡ãåé¿ã§ããŸãã
ãªããŒã¹ãããã·ã®èåŸã«ãã Jira
Jira ã Apache ã®ãããªãªããŒã¹ãããã·ã®èåŸã«ãã¹ããããŠããå Žåã®è©³çŽ°ã«ã€ããŠã¯ãSSL ã«ãã£ãŠ Jira ãš Apache ãçµ±åãããããåç §ãã ããã
æ°ããæ¥ç¶ã®è¿œå
SSL ãªã©ã®æ°ããæ¥ç¶ãè¿œå ããéã«ãJira èšå®ããŒã«ã¯æ¥ç¶ã®è©³çŽ°ãå«ããšã³ããªã server.xml
ãã¡ã€ã«ã«ä¿åããŸãããã®ãšã³ããªã¯ç¹æ®æåãåŠçããããããã£ãå«ãŸãªããããæåã§è¿œå ããå¿
èŠããããŸãããã®ããããã£ããªããã° Jira ã¯é©åã«æ©èœããªããããããã¯å¿
é ã®æäœã§ãã以éã§å¿
èŠãªæé ã説æããŸãã詳现ã«ã€ããŠã¯ãã¡ããã芧ãã ããã
å®å šæ§ãäœã BKS-V1 ããŒã¹ãã¢åœ¢åŒ
BouncyCastle ã©ã€ãã©ãªã§æäŸããã BKS-V1 ããŒã¹ãã¢åœ¢åŒã«ã¯ã»ãã¥ãªãã£ã®è匱æ§ãããããããå©çšã® Jira ã€ã³ã¹ã¿ã³ã¹ã§ã¯äœ¿çšããªãããšããå§ãããŸãã詳现æ å ±
Java ããŒã¹ãã¢ã®çæ
ã客æ§ã® SSL 蚌ææžãä¿åãã Java ããŒã¹ã㢠(JKS) ãäœæããæ¹æ³ã«ã€ããŠèª¬æããŸããSSL 蚌ææžã¯ãJira 㧠SSL éä¿¡ãè¡ãããã«ã¯å¿ é ã®ãã®ã§ããSSL 蚌ææžã¯äžè¬çã«æ¬¡ã® 2 ã€ã®çš®é¡ã«åºåãããŸãã
蚌ææž | 説æ | 䜿çšç°å¢ | æé |
---|---|---|---|
èªå·±çœ²å蚌ææž | èªèšŒå±ã«ããããžã¿ã«çœ²åããªã蚌ææžã§ããWeb ãµãŒããŒèšŒææžã®æ£åœæ§ã確èªããæ¹æ³ã§ããèªåèªèº«ãèªå·±åã§çœ²åããŸãã | ãã¹ãçšãéçºçšããã®ä»å éšåããµãŒããŒã®ã¿ | 1-13 |
CA 眲å蚌ææž | èªèšŒå± (CA) ã®ããžã¿ã«çœ²åã«ãã£ãŠæ£åœæ§ã確èªããã蚌ææžã§ããããã«ããããã©ãŠã¶ãã¯ã©ã€ã¢ã³ãã¯èšŒææžã«ä¿¡çšã眮ãããšãå¯èœã«ãªããŸãã | æ¬çªç°å¢çšãµãŒã㌠| 1-19 |
ä¿¡çšã®ããããµãŒãããŒãã£ãŒèªèšŒå± (CA) ãçºè¡ããããžã¿ã«èšŒææžã«ãããã客æ§ã® Web ãµã€ããã客æ§ã®äŒç€Ÿãæ£åœã«ä»£è¡šãããã®ã§ããããšã蚌æãããã客æ§ã®äŒç€Ÿã®å®åšãèªèšŒãããŸããå€ãã® CA ã§ã¯åã«ãã¡ã€ã³åã®ã¿ãèªèšŒãã蚌ææžãçºè¡ããŸãããVeriSign ãªã©ã§ã¯ãã客æ§ã®äºæ¥æŽ»åã®ååšããã¡ã€ã³åã®æææš©ã®ååšã蚌ææžäœ¿çšã«é¢ããã客æ§ã®æš©éãªã©ã蚌æããé«åºŠã®èªèšŒãæäŸããŠããŸãã
CA ã®äžèŠ§ã¯ããããã芧ãã ãããããç¥ãããèªèšŒå±ã®äŸã次ã«ç€ºããŸã:
åœç€ŸãšããŠã¯ãCA ã§çœ²åããã蚌ææžã®å©çšãæšå¥šããããŸãã
Portecle ãã客æ§ã®ãµãŒããŒã«ã€ã³ã¹ããŒã«ã§ããªãããŸãã¯ã³ãã³ã ã©ã€ã³ã®å©çšããåžæã®å Žåã¯ã以äžã®ãã³ãã³ã ã©ã€ã³ã«ããã€ã³ã¹ããŒã«ãã»ã¯ã·ã§ã³ããåç §ãã ããã
Portecle ã¢ããªãããŠã³ããŒãããŠãJira ãå®è¡ãããµãŒããŒã«ã€ã³ã¹ããŒã«ããŸãã
ãã®ã¢ããªã±ãŒã·ã§ã³ã¯ãµãŒãããŒãã£ãŒè£œã§ãããã¢ãã©ã·ã¢ã³ã§ã¯ãµããŒã察象å€ã§ãã
é©åãªæš©éãæã£ãŠå®è¡ã§ããããã«ãã¢ããªã管çè ãšããŠå®è¡ããŸãããŸãã
<JAVA_HOME>
å€æ°ã Jira ã§äœ¿çšãã Java ãšåãããŒãžã§ã³ã瀺ããŠããããšã確èªããŸãã詳现ã«ã€ããŠã¯ããJAVA_HOME ã®èšå®ããåç §ããŠãã ãããLinux/Unix ãµãŒããŒäžã§å®è¡ããŠããå Žåã¯ã以äžã®ããã«ãµãŒããŒã«æ¥ç¶ããéã« X11 ã転éããããšã§ GUI ãå©çšã§ããŸãã
ssh -X user@server
- [Create a new Keystore] ãéžæããŸãã
- [JKS] 圢åŒãéžæã㊠[OK] ãã¯ãªãã¯ããŸãã
- [Generate Key Pair] ãéžæããŸãã
- [Key Algorithm] ã§ã¯ [RSA] ãã[Key Size] ã§ã¯ [2048] ãéžæããŸãã
- [Signature Algorithm] ã [SHA256withRSA] ãšãªã£ãŠããããšã確èªããŸãããæ¢å®ã® SSL æå·åã匱ãããããšã«ã€ããŠã®ã»ãã¥ãªã㣠ããŒã«ããã®å ±åãããåç
§ãã ããã
以äžã®äŸã®ããã«èšŒææžã®è©³çŽ°ãç·šéã㊠[OK] ãéžæããŸãã
[Common Name] ã¯ãµãŒããŒã® URL ãšäžèŽããŠããå¿ èŠããããŸããäžèŽããªãå Žåã¯ãšã©ãŒããã©ãŠã¶ã«è¡šç€ºãããŸãã
- 蚌ææžã®ãšã€ãªã¢ã¹åãéžæããŸããäŸ:
jira
- ããŒã¹ãã¢ã®ãã¹ã¯ãŒããå
¥åããŸããæ¢å®ã®ãã¹ã¯ãŒãã¯éåžž
changeit
ã§ãã - ã㌠ãã¢ã®çæãæåããæšã®ã¡ãã»ãŒãžã衚瀺ãããŸãã
åã®ã¹ããããšåããã¹ã¯ãŒãã䜿çšãããŠããããšã確èªããŠãããŒã¹ãã¢ã
<Jira_HOME>/jira.jks
ã«ä¿åããŸãã[ãã¡ã€ã«] > [ããŒã¹ãã¢ã®ä¿å] ãéžæããŠä¿åã§ããŸããèªå·±çœ²å蚌ææžã䜿çšããå Žåã¯ããJira èšå®ããŒã«ãå©çšãã Web ãµãŒããŒã®èšå®ãã«é²ãã§ãã ããããã以å€ã®å Žåã¯æ¬¡ã®æé ã«é²ã¿ãŸãã
- 蚌ææžã®æ£åœæ§ã確èªããããã«èªèšŒå±ã«å¯ŸããŠçœ²åãäŸé Œãã蚌ææžçœ²åèŠæ± (CSR) ãçæããå¿
èŠããããŸãããããè¡ãããã«ã¯ã蚌ææžäžã§å³ã¯ãªãã¯ããŠ[CSR ã®çæ] ãéžæããŸããCSR ãã¡ã€ã«ã
<Jira_HOME>/jira.csr
ã«ä¿åããŸãã - CSR ã眲åã®ããã«èªèšŒå±ã«éä¿¡ããŸããèªèšŒå±ããã¯ã眲åæžã¿èšŒææž (CA å¿ç) ããã³ CA ã®ã«ãŒã蚌ææž/äžé蚌ææžã®ã»ãããè¿éãããŸãã
- [Import Trusted Certificate] ã§ã«ãŒã蚌ææžãšäžé蚌ææžã®äž¡æ¹ (ãããã¯çæ¹) ãã€ã³ããŒãããŸãã蚌ææžããšã«ãã®æé ãç¹°ãè¿ããŸãã
jira
蚌ææžã§å³ã¯ãªãã¯ã㊠[Import CA Reply] ãéžæãã眲åä»ã蚌ææžã®ã€ã³ããŒããéå§ããŸãã- èªèšŒå±ããæäŸããã蚌ææž (
jira.crt
) ãéžæããŸããCA å¿çã®ã€ã³ããŒããå®äºãããšããéç¥ãå±ããŸãã - çµæã [ããŒã«] > [ããŒã¹ã㢠ã¬ããŒã] ã§ç¢ºèªããŸãã蚌ææžã¯ã«ãŒã蚌ææžã®åããŒããšããŠè¡šç€ºãããŸãã
- ããŒã¹ãã¢ãä¿åãã次ã®ã»ã¯ã·ã§ã³ã«é²ã¿ãŸã :
Jira èšå®ããŒã«ãå©çšãã web ãµãŒããŒã®èšå®
Jira ã§ã® SSL æå·åèšå®ã®æåŸã®æé ãšããŠãJira èšå®ããŒã«ãå©çšã㊠Web ãµãŒããŒãèšå®ããŸããJira èšå®ããŒã«ã®è©³çŽ°ã¯ããJira èšå®ããŒã«ã®å©çšããã芧ãã ããã
- 次ã®ããã« Jira èšå®ããŒã«ãå®è¡ããŸãã
- Windows: ã³ãã³ã ããã³ãããéããŠãJira ã€ã³ã¹ããŒã« ãã£ã¬ã¯ããªã®
bin
ãµããã£ã¬ã¯ããªã«ããconfig.bat
ãå®è¡ããŸãã Linux/Unix: ã³ã³ãœãŒã«ãéããŠãJira ã€ã³ã¹ããŒã« ãã£ã¬ã¯ããªã®
bin
ãµããã£ã¬ã¯ããªã«ããconfig.sh
ãå®è¡ããŸãããã®ã³ãã³ãã¯ãNo X11 DISPLAY å€æ°ãåå 㧠Jira ã¢ããªã±ãŒã·ã§ã³èšå®ããŒã«ãèµ·åã§ããªãã£ãã®ã¯ãèšå®ãšã©ãŒã«ãããã®ãã«èšèŒã®ãšã©ãŒã§å€±æããå ŽåããããŸãããã®å Žåã¯ããã®èšäºã®åé¿çããåç §ãã ããã
- Windows: ã³ãã³ã ããã³ãããéããŠãJira ã€ã³ã¹ããŒã« ãã£ã¬ã¯ããªã®
- [Web ãµãŒããŒ] ãéžæããŸãã
ã¹ã¯ãªãŒã³ã·ã§ãã: Jira èšå®ããŒã« â [Web ãµãŒããŒ] ã¿ã åãã£ãŒã«ãã«æ¬¡ã®ããã«å ¥åããŸã :
ãã£ãŒã«ã å€ ããŒãã®å¶åŸ¡ éåžžã¯åæèšå®ã®ãŸãŸãšããŸããå¿ èŠã«å¿ããŠããŒãçªå·ãå€æŽããããšãã§ããŸãã詳现ã¯ãJira ã® TCP ããŒãã®å€æŽããã芧ãã ããã ãããã£ãŒã« ãããã¡ã€ã«ãšã¯ããªã»ããããã Web ãµãŒããŒåäœèšå®ã§ãã次㮠4 ã€ã®å€ããéžæã§ããŸãã - ç¡å¹
- HTTP ã®ã¿
- HTTP ããã³ HTTPS (HTTP ã HTTPS ãžãªãã€ã¬ã¯ã)
- HTTPS ã®ã¿
Jira ã HTTPS äžã§å®è¡ããå Žåã¯ã[HTTP & HTTPS] ãŸã㯠[HTTPS] ãéžæããå¿ èŠããããŸãã
Jira ã HTTPS äžã§å®è¡ãããããŠãŒã¶ãŒã HTTP çµç±ã§ã Jira ã¢ã¯ã»ã¹ã§ããããã«ããå Žåã¯ã[HTTP & HTTPS] ãéžæããŠãã ããããã®å ŽåãHTTP çµç±ã§ Jira ã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã¯ HTTPS ã®ã¢ãã¬ã¹ã«ãªãã€ã¬ã¯ããããŸãã
HTTP ããŒã éåžžã¯åæèšå®ã®
8080
ã®ãŸãŸã«ããŸããå¿ èŠã«å¿ããŠããŒãçªå·ãå€æŽããããšãã§ããŸãã詳现ã¯ãJira ã® TCP ããŒãã®å€æŽããã芧ãã ããã[ãããã¡ã€ã«] 㧠[HTTPS ã®ã¿] ãéžæããå Žåã¯ãã®ãã£ãŒã«ãã¯ç¡å¹ã«ãªããŸãã
HTTPS ããŒã éåžžã¯åæèšå®ã® 8443
ã®ãŸãŸã«ããŸããå¿ èŠã«å¿ããŠããŒãçªå·ãå€æŽããããšãã§ããŸãã詳现ã¯ãJira ã® TCP ããŒãã®å€æŽããã芧ãã ãããKeystore ã㹠蚌ææžã®ããŒã¹ãã¢ã®å Žæãæå®ããŸããããã¯ãããŒã¹ãã¢ãä¿åããéã«çæãããå Žæã§ã
<Jira_HOME>/jira.jks
ã§ããKeystore ãã¹ã¯ãŒã ããŒã¹ãã¢ã®ãã¹ã¯ãŒããæå®ããŸããèªå·±çœ²å蚌ææžãçæããå Žåã¯ããã®ãã¹ã¯ãŒãã¯èšŒææžãçæããŠä¿åãããšãã«ããŒããã³ããŒã¹ãã¢ã«èšå®ãããã¹ã¯ãŒãã§ãã Keystore ãšã€ãªã¢ã¹ ããŒã¹ãã¢å ã®ããããã®é ç®ã¯ãšã€ãªã¢ã¹ã§åºå¥ãããŸãã蚌ææžã«ã€ã㊠jira
ã䜿çšããããšãæšå¥šããŸãã- ç¡å¹
- [Check Certificate in Key Store (ããŒã¹ãã¢ã®èšŒææžããã§ãã¯ãã)] ãéžæããŠã次ã®é
ç®ã確èªããŸãã
- ããŒã¹ãã¢å ã«èšŒææžãååšããããšã
- ããŒã¹ãã¢ã®ãã¹ã¯ãŒããæå¹ã§ããããšã
- ã㌠ãšã€ãªã¢ã¹ã䜿çšããŠããŒãèŠã€ããããããšã
- å€æŽãä¿åããŸãã
æ°ããæ¥ç¶ã®è¿œå æã«ãèšå®ããŒã«ã«ã¯ç¹æ®æåãèš±å¯ããããããã£ãå«ãŸããªãããããããã server.xml
ãã¡ã€ã«ã«æåã§è¿œå ããå¿
èŠããããŸããæ¹æ³ã®è©³çŽ°ã«ã€ããŠã¯ãã¡ãã®èšäºããåç
§ãã ããã
é«åºŠãªèšå®
åäžãã¹ãã«ãããè€æ°ã®ã€ã³ã¹ã¿ã³ã¹ã®å®è¡
åäžãã¹ãã§è€æ°ã®ã€ã³ã¹ã¿ã³ã¹ãå®è¡ããå Žåã¯ãaddress å±æ§ã <Jira_INSTALLATION>/conf/server.xml
ãã¡ã€ã«ã§æå®ããŸããæ¢å®ã§ã¯ã³ãã¯ã¿ã¯å©çšå¯èœãªãã¹ãŠã®ãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹äžã§ãªãã¹ã³ããŠãããåäžã®æ¢å®ããŒãäžã§å®è¡ãããã³ãã¯ã¿éã®è¡çªãé²æ¢ããããã«ã¢ãã¬ã¹ãæå®ããå¿
èŠãããããã§ããaddress å±æ§ã®èšå®ã®è©³çŽ°ã«ã€ããŠã¯ãApache Tomcat ããã¥ã¡ã³ãã®ãThe HTTP Connectorããã確èªãã ããã
ã³ãã³ã ã©ã€ã³ã䜿çšããã€ã³ã¹ããŒã«
ã¹ããã 1.ããŒã¹ãã¢ãäœæããŸã
Java ããŒã¹ãã¢ãçæããŸãã
<JAVA_HOME>/keytool -genkey -alias jira -keyalg RSA -keystore <Jira_HOME>/jira.jks
å§å (first and last names) ã®éšåã«ã¯ããµãŒããŒã® URL ãããhttps://ããé€ãããã® (jira.atlassian.com ãªã©) ãæå®ããŸãã
- ãã¹ã¯ãŒããå ¥åããŸãã
æé 2 ã®ãã¹ã¯ãŒãã䜿çšããŠã眲åã®ããã® CSR ãçæããŸãã
<JAVA_HOME>/keytool -certreq -alias jira -file /output/directory/csr.txt -keystore <Jira_HOME>/jira.jks
CSR ã眲åã®ããã«èªèšŒå±ã«éä¿¡ããŸããèªèšŒå±ããã¯ã眲åæžã¿èšŒææžãš CA ã®ã«ãŒã蚌ææžãŸãã¯äžé蚌ææžãè¿éãããŸãã
蚌ææžã眲åãããŠããªãå Žåã¯ããKeystore 㧠Tomcat ãæŽæ°ããããŸã§ã¹ãããããŸãã
ã«ãŒã蚌ææžããŸãã¯äžé蚌ææžãã€ã³ããŒãããŸãã
<JAVA_HOME>/keytool -import -alias rootCA -keystore <Jira_HOME>/jira.jks -trustcacerts -file root.crt
èªèšŒå±ããè¿éããã眲åæžã¿èšŒææžãã€ã³ããŒãããŸãã
<JAVA_HOME>/keytool -import -alias jira -keystore <Jira_HOME>/jira.jks -file jira.crt
ããŒã¹ãã¢å ã«èšŒææžãååšããããšã確èªããŸãã
<JAVA_HOME>/keytool -list -alias jira -keystore <Jira_HOME>/jira.jks
ããã¯
PrivateKeyEntry
ã§ããå¿ èŠããããŸããç°ãªãå Žåã蚌ææžã®ã»ããã¢ãããæ£åžžã«å®äºããŠããŸããã次ã«äŸã瀺ããŸããjira, Jan 1, 1970, PrivateKeyEntry, Certificate fingerprint (MD5): 73:68:CF:90:A8:1D:90:5B:CE:2A:2F:29:21:C6:B8:25
ã¹ããã 2.Keystore 㧠Tomcat ãæŽæ°ãã
- ç·šéããåã«ã
<Jira_INSTALL>/conf/server.xml
ã®ããã¯ã¢ãããäœæããŸãã HTTPS ã³ãã¯ã¿ãç·šéããããŒã¹ãã¢ã瀺ããã©ã¡ãŒã¿ãŒãå«ããŸãã
<Connector relaxedPathChars="[]|" relaxedQueryChars="[]|{}^\`"<>" port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxHttpHeaderSize="8192" SSLEnabled="true" maxThreads="150" minSpareThreads="25" enableLookups="false" disableUploadTimeout="true" acceptCount="100" scheme="https" secure="true" sslEnabledProtocols="TLSv1.2,TLSv1.3" clientAuth="false" useBodyEncodingForURI="true" keyAlias="jira" keystoreFile="<Jira_HOME>/jira.jks" keystorePass="changeit" keystoreType="JKS"/>
é©åãªãã¹ã
<Jira_HOME>
ã«å ¥åããŠãå¿ èŠã«å¿ããŠããŒããå€æŽããŸããçµç¹ãææ°ã® TLS ããŒãžã§ã³ããµããŒãããŠããªãå Žåã¯ã以åã®ããŒãžã§ã³ãžãã©ãŒã«ããã¯ã§ããŸãã次ã®ããã«å€æŽããŸãã
sslEnabledProtocols="TLSv1.2,TLSv1.3"
to
sslEnabledProtocols="TLSv1,TLSv1.1,TLSv1.2,TLSv1.3"
HTTP ã³ãã¯ã¿ãç·šéããHTTPS ã³ãã¯ã¿ãžãªãã€ã¬ã¯ãããããã«ããŸãã
<Connector relaxedPathChars="[]|" relaxedQueryChars="[]|{}^\`"<>" acceptCount="100" connectionTimeout="20000" disableUploadTimeout="true" enableLookups="false" maxHttpHeaderSize="8192" maxThreads="150" minSpareThreads="25" port="8080" protocol="HTTP/1.1" redirectPort="<PORT_FROM_STEP_1>" useBodyEncodingForURI="true"/>
<PORT_FROM_STEP_1>
ãé©åãªå€ã«å€æŽãããŠããããšã確èªããŸãããã®äŸã§ã¯8443
ã§ãã- å€æŽã
server.xml
ã«ä¿åããŸãã HTTPS ãžã®ãªãã€ã¬ã¯ãã䜿çšããå Žå (æšå¥š)ã
Jira_INSTALL>/WEB-INF/web.xml
ãã¡ã€ã«ãç·šéãããã¡ã€ã«ã®æ«å°Ÿã«æ¬¡ã®ã»ã¯ã·ã§ã³ãè¿œå ããŠããã</web-app>
ãéããŸãããã®äŸã§ã¯ãæ·»ä»ãã¡ã€ã«ãé€ããã¹ãŠã® URL ã HTTP ãã HTTPS ã«ãªãã€ã¬ã¯ããããŸãã<security-constraint> <web-resource-collection> <web-resource-name>all-except-attachments</web-resource-name> <url-pattern>*.jsp</url-pattern> <url-pattern>*.jspa</url-pattern> <url-pattern>/browse/*</url-pattern> <url-pattern>/issues/*</url-pattern> </web-resource-collection> <user-data-constraint> <transport-guarantee>CONFIDENTIAL</transport-guarantee> </user-data-constraint> </security-constraint>
- å€æŽå 容ãä¿åã㊠Jira ãåèµ·åããŸãã
ãŸããJira èšå®ããŒã«ã§ãHTTP ãš HTTPSããããã¡ã€ã«ãéžæããŠãHTTP URL ãã HTTPS URL ãžãŠãŒã¶ãŒããªãã€ã¬ã¯ãããããšãã§ããŸãã
ç¹å®ã®ããŒãžã®ã¿ã HTTPS ãžãªãã€ã¬ã¯ããããå Žåã¯æåã§è¡ãå¿ èŠããããŸãã
- Jira èšå®ããŒã«ã§ãHTTPS ã®ã¿ããããã¡ã€ã«ãéžæããŠèšå®ãä¿åããŸãã
- HTTP URL ã察å¿ãã HTTPS URL ã«ãªãã€ã¬ã¯ããã Web ãµãŒããŒäžã«
htaccess
ãã¡ã€ã«ãäœæããŸãã
ãã©ãã«ã·ã¥ãŒãã£ã³ã°
äžèšã«ããéã Portecle ãçšããŠçæããèªå·±çœ²åããŒã䜿çšããå Žåã®ããã©ãã«ã·ã¥ãŒãã£ã³ã°ã® TIPS ãããã€ã玹ä»ããŸãã
ãã©ãŠã¶ã«ãhttps://localhost:<port number>
ããšå
¥åãããšãã«ãCannot establish a connection to the server at localhost:8443ãã®ãããªã¡ãã»ãŒãžã衚瀺ãããå Žåã¯ãlogs/catalina.out
ãã° ãã¡ã€ã«ã§ãšã©ãŒ ã¡ãã»ãŒãžãæ¢ããŸããããã§ã¯çºçããå¯èœæ§ãããããã€ãã®ãšã©ãŒãšããããã®èª¬æã玹ä»ããŸãã
ãã®å 容ã¯ã圹ã«ç«ã¡ãŸããã?
ã¯ã ãã®èšäºã«ã€ããŠã®ãã£ãŒãããã¯ãéä¿¡ãã