# SSL On Red Hat® Enterprise Linux® 8.3

**URL:** <https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302>\
**Category:** Using Jenkins\
**Created:** [May 10, 2023, 9:01pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302 "2023-05-10T21:01:31Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 10, 2023, 9:01pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/1 "2023-05-10T21:01:31Z")

</div>

I followed the step by step guide on installing SSL using port 8443 on to the Linux Jenkins server as shown below:  
Let’s create a folder and move the jenkins.jks key to that location.  
mkdir -p /etc/jenkins  
cp jenkins.jks /etc/jenkins/  
Change the permissions of the keys and folder.  
chown -R jenkins: /etc/jenkins  
chmod 700 /etc/jenkins  
chmod 600 /etc/jenkins/jenkins.jks  
**Step 5: Modify Jenkins Configuration for SSL**  
All the key Jenkins startup configurations are present in /etc/sysconfig/jenkins file. All the SSL-based configurations go into this file.  
Open the file  
sudo vi /etc/sysconfig/jenkins  
Find and replace the values in the file as shown below.  
**Note:** Replace your-keystore-password with the Keystore password, you set in step 3. Also you can use either 443 or 8443 for ports.  
JENKINS\_PORT=“-1”  
JENKINS\_HTTPS\_PORT=“8443”  
JENKINS\_HTTPS\_KEYSTORE=“/etc/jenkins/jenkins.jks”  
JENKINS\_HTTPS\_KEYSTORE\_PASSWORD=“”  
JENKINS\_HTTPS\_LISTEN\_ADDRESS=“0.0.0.0”  
Save the configuration and restart Jenkins.  
sudo systemctl restart jenkins  
Check Jenkins status.  
sudo systemctl status jenkins  
**Step 6: Validate SSL**  
Now you should be able to access Jenkins over HTTPS with port 8443  
https://\<jenkins-dns/ip\>:8443

When I try to validate it get an error that the site can’t be reached and it says site took too long to respond ERR\_CONNECTION\_TIMED\_OUT.  
Not sure why this is happening…does the jenkins.jks file need to go into the Jenkins home directory /var/lib/jenkins? or am I missing a step somewhere in this configuration and getting it to point to 8443 instead of 8080 by default?

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [May 10, 2023, 9:03pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/2 "2023-05-10T21:03:43Z")

</div>

> [@jenkinsnewbe](#):
>
> ERR\_CONNECTION\_TIMED\_OUT

are you sure there’s no firewall or loadbalancer dropping that port? Connection refused is usually when something isn’t listening, timed out means the connection is still open but never returned.

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 10, 2023, 9:42pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/3 "2023-05-10T21:42:20Z")

</div>

No firewall or anything blocking that we can see…however when we look on the system I don’t see port 8443 listening…Could it be that if we leave port 8080 on 0.0.0.0 and port 8443 on the same ip address it will not work? Do I need to switch to like 127.0.0.1?

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 10, 2023, 9:51pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/4 "2023-05-10T21:51:17Z")

</div>

Guessing that port 8443 not listening is the issue, so where am I missing getting that port to listen? If it is listening I assume it will work?

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [May 10, 2023, 9:58pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/5 "2023-05-10T21:58:04Z")

</div>

> [@jenkinsnewbe](#):
>
> Open the file  
> sudo vi /etc/sysconfig/jenkins

Hi there,

Jenkins 2.332.1 switched Jenkins from using System V init to use systemd with its Linux package installers for Debian, Ubuntu, Red Hat, Alma, openSUSE, Rocky, and more. The [LTS Upgrade Guide](https://www.jenkins.io/doc/upgrade-guide/2.332/#upgrading-to-jenkins-lts-2-332-1) describes that transition and how to adapt your environment to the transition.

> **[Upgrading to Jenkins LTS 2.332.x](https://www.jenkins.io/doc/upgrade-guide/2.332/#upgrading-to-jenkins-lts-2-332-1)**
>
> Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software

There is a [blog post](https://www.jenkins.io/blog/2022/03/25/systemd-migration/) about it as well at

> **[Linux installation packages migrated from System V init to systemd](https://www.jenkins.io/blog/2022/03/25/systemd-migration/)**
>
> Starting with Jenkins 2.335, the Jenkins project is migrating from System V init to systemd.

There is also a [video introduction](https://www.youtube.com/watch?v=MkokjTQ2ngc) for RPM based distributions like Red Hat Enterprise Linux, Alma Linux, Rocky Linux, Oracle Linux, and Amazon Linux.

[![](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/5/5d731f86134683079a41351908d8832c01e0a6f4.jpeg "🔴 Managing the Jenkins systemd Service on CentOS 7.9") ](https://www.youtube.com/watch?v=MkokjTQ2ngc)

There is also a [video introduction](https://www.youtube.com/watch?v=pwR9TPW2oG4) for deb based distributions like Debian and Ubuntu

[![](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/0/04a2972bcb9f7e4756fdc406b9992a75a8f47ed2.jpeg "🔴 Managing the Jenkins systemd Service on Ubuntu 20.04") ](https://www.youtube.com/watch?v=pwR9TPW2oG4)

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 11, 2023, 1:58pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/6 "2023-05-11T13:58:53Z")

</div>

Yes we are using 2.387.1 version

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 11, 2023, 2:03pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/7 "2023-05-11T14:03:09Z")

</div>

![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/2/2829ba2b6d34b2fe3eee24b73ec8a20016bd95de.png)

Is it telling me the override.conf is disabled? and is the --httpPort=8080 overriding the https setting in the override.conf file?

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 11, 2023, 2:41pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/8 "2023-05-11T14:41:03Z")

</div>

I have tried using the override.conf file and even directly editing the jenkins.service file in /usr/lib/systemd/system/jenkins.service. Regardless, adding the various envvar statements makes no difference to the running jenkins instance upon restart. It continues to ONLY listen on port 8080 nothing on port 8443?

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 11, 2023, 3:16pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/9 "2023-05-11T15:16:35Z")

</div>

The disabled state indicates whether the service is set to start automatically upon reboot. As it says disabled, it will not start up auttomatically. So that is answered, still don’t know why 8443 is overridden and only port 8080 works?

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [May 11, 2023, 3:27pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/10 "2023-05-11T15:27:22Z")

</div>

if you look at your process tree (ps xf -A is my goto), what do all the command line arguments look like? does it list 8443? Trying to figure out if its not reading the variables, or something else.

I’ve never added https directly to jenkins before. I always use a reverse proxy like nginx to do ssl termination.

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 11, 2023, 6:56pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/11 "2023-05-11T18:56:27Z")

</div>

I don’t see anything related to port 8443 on the output of the ps xf -A command. Only 8080:

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/jenkins/original/2X/c/cea59c7f29de23ce29ece37f5ffe7fcef9f1b5c7.png)

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [May 11, 2023, 10:37pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/12 "2023-05-11T22:37:33Z")

</div>

That seems to be a problem

can you share the output of your systemctl edit jenkins?

I don’t use any of this functionality myself (I use docker), so we’d need to figure out which variables jenkins actually listens to, but i’m thinking checking if systemd file is correct is a good first step.

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 15, 2023, 4:31pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/13 "2023-05-15T16:31:42Z")

</div>

[Service]  
JENKINS\_HOME=“/var/lib/jenkins”  
JENKINS\_JAVA\_CMD=“”  
JENKINS\_USER=“jenkins”  
JENKINS\_JAVA\_OPTIONS=“-Djava.awt.headless=true”  
JENKINS\_PORT=“-1”  
JENKINS\_LISTEN\_ADDRESS=“0.0.0.0”  
JENKINS\_HTTPS\_PORT=“8443”  
JENKINS\_HTTPS\_KEYSTORE=“/etc/jenkins/jenkins.jks”  
JENKINS\_HTTPS\_KEYSTORE\_PASSWORD=“Password!”  
JENKINS\_HTTPS\_LISTEN\_ADDRESS=“0.0.0.0”  
JENKINS\_HTTP2\_PORT=“”  
JENKINS\_HTTP2\_LISTEN\_ADDRESS=“”  
JENKINS\_DEBUG\_LEVEL=“5”  
JENKINS\_ENABLE\_ACCESS\_LOG=“no”  
JENKINS\_ARGS=“”

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [May 15, 2023, 4:51pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/14 "2023-05-15T16:51:01Z")

</div>

> <https://serverfault.com/questions/413397/how-to-set-environment-variable-in-systemd-service>

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 15, 2023, 5:44pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/15 "2023-05-15T17:44:25Z")

</div>

The information I sent you is from the override.conf file, so not sure how the set environment variable helps?

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [May 16, 2023, 5:53am UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/16 "2023-05-16T05:53:05Z")

</div>

Before the systemd migration, the config was loaded as env variables in the script. I’m assuming it still works that way. I recommend watching the video from the original canned response. It’ll know more

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 22, 2023, 4:15pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/17 "2023-05-22T16:15:01Z")

</div>

was a semantics error…  
had: JENKINS\_HTTPS\_PORT=“8443”  
has to be  
Environment="JENKINS\_HTTPS\_PORT=“8443”

Another questions so when I go to [https://jenkins.com:8443](https://jenkins.com:8443) it works fine but when I click on Log In it goes back to port 8080 and http. Is that because I have to tell the system that it is [https://jenkins.com:8443](https://jenkins.com:8443) in the system config or is it that I have to shut down port 8080 and use the JENKINS\_HTTPS\_LISTEN\_ADDRESS=“JENKINS\_PORT=-1” to shut that from happening…right now I still have 8080 enabled?

---

<div class="post-metadata">

**Author:** ![jenkinsnewbe](https://avatars.discourse-cdn.com/v4/letter/j/77aa72/32.png) [@jenkinsnewbe](https://community.jenkins.io/u/jenkinsnewbe)\
**Post date:** [May 22, 2023, 4:25pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/18 "2023-05-22T16:25:13Z")

</div>

Sorry make that Environment=“JENKINS\_PORT=-1” to disable the http port?

---

<div class="post-metadata">

**Author:** ![sincerelysaucy](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/sincerelysaucy/32/8136_2.png) [@sincerelysaucy](https://community.jenkins.io/u/sincerelysaucy)\
**Post date:** [May 8, 2024, 11:58am UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/19 "2024-05-08T11:58:18Z")

</div>

Can this be retitled? “Linux Redhat 8.3” would be Red Hat Linux 8.3 never existed, there was only Red Hat Linux 8.0 back in 2002. And yes, the names of Red Hat releases are confusing. This article is actually about RHEL 8.3, and the first few answers refer to seriously obsolete SysV based configurations which are no longer relevant with current Jenkins versions.

---

<div class="post-metadata">

**Author:** ![MarkEWaite](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/markewaite/32/20_2.png) [@MarkEWaite](https://community.jenkins.io/u/MarkEWaite)\
**Post date:** [May 8, 2024, 6:59pm UTC](https://community.jenkins.io/t/ssl-on-red-hat-enterprise-linux-8-3/7302/20 "2024-05-08T18:59:14Z")

</div>

I’ve changed the title to use the approved form of “Red Hat® Enterprise Linux®” as described in the “Product names and trademark usage” section of

> **[Naming and trademarks - Red Hat brand standards](https://www.redhat.com/en/about/brand/standards/naming-and-trademarks)**
>
> Follow these naming and trademark guidelines when referring to—and creating new names for—Red Hat entities.
