Jenkins Vulnerability | Plain Text Authentication

27 views
Skip to first unread message

Rajesh Kapur

unread,
Nov 19, 2016, 5:38:45 AM11/19/16
to Jenkins Users
Hi,

We are facing plain text vulnerability for our Jenkins. To resolve the same we need to run jenkins on HTTPS.

Now after implementing Jenkins on HTTPS, reverse proxy stops working. The certificate we have on our reverse proxy website is different than what we have for localhost.

Is there any way we can run Jenkins on URL instead of localhost?

Thanks,
Rajesh Kapur

Ismael Angelo Casimpan

unread,
Nov 19, 2016, 6:13:47 AM11/19/16
to jenkins...@googlegroups.com
Hi,

Have you tried fixing the certificate? I assume you are using a self-signed certificate (details of creating it is quite easy to find via google search).

Thanks,
Ismael

--
You received this message because you are subscribed to the Google Groups "Jenkins Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-users+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-users/d9f9d97c-4306-4ffb-a186-b7dd1aae5bb4%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Rajesh Kapur

unread,
Nov 19, 2016, 6:23:06 AM11/19/16
to jenkins...@googlegroups.com
Hi,

Yes I have created one self signed certificate and able to successfully browse jenkins on https://localhost:port/.

Now the issue is we have our Jenkins URL on public domain say, dev.myjenkins.com with certificate with domain myjenkins.com. But after setting up Jenkins on HTTPS reverse proxy stops working. Seems reverse proxy was not able to get the content from https:\\localhost.

Can I run Jenkins directly on some domain name instead of localhost?

--
You received this message because you are subscribed to a topic in the Google Groups "Jenkins Users" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/jenkinsci-users/xjn7egA1QX4/unsubscribe.
To unsubscribe from this group and all its topics, send an email to jenkinsci-users+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-users/CACvygnPU8Je1pYKBagi5i3EWHhYn%2B47H-1PDNo5BbYPeGthPRg%40mail.gmail.com.
Reply all
Reply to author
Forward
0 new messages