Confluence 3.5 : Using Apache to limit access to the Confluence administration interface
This page last changed on Apr 15, 2010 by rosie@atlassian.com.
Limiting administration to specific IP addressesThe Confluence administration interface is a critical part of the application; anyone with access to it can potentially compromise not only the Confluence instance but the entire machine. As well as limiting access to users who really need it, and using strong passwords, you should consider limiting access to it to certain machines on the network or internet. If you are using an Apache web server, this can be done with Apache's Location functionality as follows: 1. Create a file that defines permission settingsThis file can be in the Apache configuration directory or in a system-wide directory. For this example we'll call it "sysadmin_ips_only.conf". The file should contain the following: Order Deny,Allow Deny from All # Mark the Sysadmin's workstation Allow from 192.168.12.42 2. Add the file to your Virtual HostIn your Apache Virtual Host, add the following lines to restrict the administration actions to the Systems Administrator:
<Location /confluence/admin> Include sysadmin_ips_only.conf </Location> <Location /confluence/plugins/servlet/oauth/consumers/list> Include sysadmin_ips_only.conf </Location> <Location /confluence/plugins/servlet/oauth/view-consumer-info> Include sysadmin_ips_only.conf </Location> <Location /confluence/plugins/servlet/oauth/service-providers/list> Include sysadmin_ips_only.conf </Location> <Location /confluence/plugins/servlet/oauth/service-providers/add> Include sysadmin_ips_only.conf </Location> <Location /confluence/plugins/servlet/oauth/consumers/add> Include sysadmin_ips_only.conf </Location> <Location /confluence/plugins/servlet/oauth/consumers/add-manually> Include sysadmin_ips_only.conf </Location> <Location /confluence/plugins/servlet/oauth/update-consumer-info> Include sysadmin_ips_only.conf </Location> <Location /confluence/pages/templates/listpagetemplates.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/pages/templates/createpagetemplate.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/spaces/spacepermissions.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/pages/listpermissionpages.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/spaces/removespace.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/spaces/importmbox.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/spaces/viewmailaccounts.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/spaces/addmailaccount.action?> Include sysadmin_ips_only.conf </Location> <Location /confluence/spaces/importpages.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/spaces/flyingpdf/flyingpdf.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/spaces/exportspacehtml.action> Include sysadmin_ips_only.conf </Location> <Location /confluence/spaces/exportspacexml.action> Include sysadmin_ips_only.conf </Location> |
![]() |
Document generated by Confluence on Mar 16, 2011 18:29 |