-
Suggestion
-
Resolution: Answered
-
None
-
None
-
None
Often one wants some pages (eg. login page) to be protected via HTTPS, but then revert to plain HTTP for most pages, to avoid killing the server. The process of requiring HTTPS for some pages is described at:
http://confluence.atlassian.com/display/JIRA/Running+JIRA+over+SSL+or+HTTPS
however there doesn't seem to be a clean declarative way to force access of non-protected pages to revert to HTTP.
- is related to
-
JRASERVER-15122 Encrypt passwords sent from login portlet/page to server.
- Closed
-
CONFSERVER-4116 Support SSL for login and optional SSL for remainder of application
- Closed
-
JRASERVER-8974 Restrict cookie-based login to SSL users
- Closed