Tuesday, May 28, 13
JIRA Security And Permissions Management
Adam G. Saint-Prix
Enterprise Solutions Engineer
May 15th, 2013
Tuesday, May 28, 13
Enterprise
Update
Q & AJIRA Security
Tuesday, May 28, 13
24 x 7 Phone & Online Support
Dedicated Enterprise Support Reps
Instance Profiles
Atlassian Enterprise Community
Enterprise Webinars
Enterprise Workshops
Atlassian University
Admin Courses
Enterprise Resources
Tuesday, May 28, 13
Tuesday, May 28, 13
JIRA Admin Training
Next class:
Sept 30, 2013
San Francisco, California
Admin Courses
Tuesday, May 28, 13
Tuesday, May 28, 13
Tuesday, May 28, 13
Atlassian Confluence Blueprints Webinar
May 28, 2013
Matt Hodges
Product Marketing Manager, Confluence
Tuesday, May 28, 13
Atlassian Confluence Blueprints Webinar
Technical Workshops in Development
ConfluenceTheme Design
JIRA Upgrade Best Practices
JIRA Integrations
DVCS Concepts with Stash & Git
May 28, 2013
Matt Hodges
Product Marketing Manager, Confluence
Tuesday, May 28, 13
Atlassian Enterprise Community
Tuesday, May 28, 13
Atlassian Enterprise FAQ
www.atlassian.com/licensing/enterprise-faq
More Questions?
http://www.atlassian.com/software/enterprise/overview/
contactus
Upgrade to Enterprise?
my.atlassian.com/purchase/
Tuesday, May 28, 13
Enterprise
Update
Q&AJIRA Security
Tuesday, May 28, 13
Enterprise
Update
Q&AJIRA Security
Tuesday, May 28, 13
Tuesday, May 28, 13
Security and Permissions
Management
Tuesday, May 28, 13
Exposure
• Balance usability and security
• Public internet vs. internal network
• Encryption
Tuesday, May 28, 13
Server Best Practices
• Named Users
• Strong Passwords
• at least 15 characters
• uppercase letters
• lowercase letters
• numbers
• Keys
• sudo
• Don’t run as root
Remember:	
  A"ackers	
  are	
  good	
  at	
  finding	
  the	
  cracks
8I=</-53UR>t(n5
Tuesday, May 28, 13
Firewalls and Routing
• Incoming Ports: 80, 443, 22
• Outgoing Ports? (smtp, pop/imap, db)
• No route to backend systems
Credit: NIST, modified by cpepe
sshd
JIRA	
  Server
DB	
  Server
RouterFirewall
A"acker
Tuesday, May 28, 13
Open Ports, strong daemons
• IDS
• Monitoring
• Firewall
• Routing
Tuesday, May 28, 13
SSL - Considerations
• Terminate in apache or tomcat?
• Application Links
• Make life easier
Tuesday, May 28, 13
SSL is tough
• Black box
• Chip away at it ‘til it works
• Hope to never touch it again (document because you will)
• Do it right, it protects you
Tuesday, May 28, 13
Why use SSL?
• Always for public facing systems
• Optional, recommended ‘behind the firewall’
• Optional, recommended for backend systems
h"ps://confluence.atlassian.com/display/JIRA/Running+JIRA+over+SSL+or+HTTPS
Running	
  JIRA	
  over	
  SSL	
  or	
  HTTPS:
Helpful Atlassian resources:
h"ps://confluence.atlassian.com/display/JIRA/IntegraIng+JIRA+with+Apache
IntegraIng	
  JIRA	
  with	
  Apache:
h"ps://confluence.atlassian.com/display/JIRA/Installing+JIRA+on+Linux
Installing	
  JIRA	
  on	
  Linux:
h"ps://confluence.atlassian.com/display/JIRA/Tomcat+security+best+pracIces
Tomcat	
  Security	
  Best	
  PracIces:
* While Atlassian does provide some documents for SSL and Apache, Atlassian cannot guarantee providing support for these custom configurations
Tuesday, May 28, 13
JIRA Security
Administration
Tuesday, May 28, 13
System Administrator
Ability to perform all administration functions.There must be at least one group with
this permission.
JIRA Administrator
Ability to perform most administration functions (excluding Import & Export, SMTP
Configuration, etc.).
Project Administrator
This includes the ability to edit project role membership, project components, project
versions and some project details ('Project Name', 'URL', 'Project Lead', 'Project
Description').
Application Administration
Tuesday, May 28, 13
Voters&WatchersandTimeTrackingPermissionsomitted
Permissions
Scheme
Tuesday, May 28, 13
Workflow Conditions
Tip:	
  Using	
  roles	
  makes	
  workflows	
  	
  more	
  reusable
Tuesday, May 28, 13
Issue Security
Tuesday, May 28, 13
Issue Security
JIRA	
  hides	
  what	
  we	
  don’t	
  have	
  permission	
  to	
  see
Tuesday, May 28, 13
Questions?
Tuesday, May 28, 13
Thank you!
Tuesday, May 28, 13

More Related Content

PPTX
What Is DevOps?
PDF
Product Management by Numbers: Using Metrics To Optimize Your Product by Dan ...
PDF
Agile Testing Framework - The Art of Automated Testing
PDF
PDF
Jira 101
PDF
Webdriver io presentation
PPTX
AI Testing What Why and How To Do It?
PDF
JIRA_Manual_Vol.1
What Is DevOps?
Product Management by Numbers: Using Metrics To Optimize Your Product by Dan ...
Agile Testing Framework - The Art of Automated Testing
Jira 101
Webdriver io presentation
AI Testing What Why and How To Do It?
JIRA_Manual_Vol.1

What's hot (20)

PPTX
Strategies to Overcome Self-Doubt at Work
PPTX
Lean Startup Tools for Agile Product Teams
PPT
Success Mindset
PPTX
TestOps and Shift Left
PPSX
PDF
An Introduction to Generative AI
PPTX
DevOps seminar ppt
PDF
Fixed Mindset and Growth Mindset
PPTX
Observability, what, why and how
PDF
Api observability
PDF
Introduction To Confluence
PDF
PantaRei Design Limited - JIRA Software Introduction - Project - Workflow - D...
PPTX
What the heck is Product-led Growth?
PDF
Transforming Your QA and Test Team
PPTX
How to Chat Gpt Works?
PDF
Karate - Web-Service API Testing Made Simple
PDF
Unlocking the Power of ChatGPT and AI in Testing - NextSteps, presented by Ap...
PDF
DevSecOps
PPT
CI and CD with Jenkins
PPT
Role Of Qa And Testing In Agile 1225221397167302 8
Strategies to Overcome Self-Doubt at Work
Lean Startup Tools for Agile Product Teams
Success Mindset
TestOps and Shift Left
An Introduction to Generative AI
DevOps seminar ppt
Fixed Mindset and Growth Mindset
Observability, what, why and how
Api observability
Introduction To Confluence
PantaRei Design Limited - JIRA Software Introduction - Project - Workflow - D...
What the heck is Product-led Growth?
Transforming Your QA and Test Team
How to Chat Gpt Works?
Karate - Web-Service API Testing Made Simple
Unlocking the Power of ChatGPT and AI in Testing - NextSteps, presented by Ap...
DevSecOps
CI and CD with Jenkins
Role Of Qa And Testing In Agile 1225221397167302 8
Ad

Viewers also liked (16)

PPT
Jira customization
PDF
Atlassian Certified JIRA Administrator certificate
PDF
Large Scale JIRA Administration
PPTX
Jira Basic Concepts
PDF
Atlassian Certified JIRA Administrator
PDF
Enterprise workshops agile concepts jira green hopper atlassian deck
PPTX
JIRA Introduction | JIRA Tutorial | Atlassian JIRA Training | H2kinfosys
PPTX
JIRA System Admin Traning
PPTX
Agile Project and Portfolio Management Using Jira - AgileSolutions
PDF
Adapting JIRA For Scrum
PPTX
Jira fundamentals
PPTX
Jira as a Tool for Test Management
PPT
Using JIRA Software for Issue Tracking
PDF
Introduction To Jira
PDF
Introduction to JIRA & Agile Project Management
PDF
Jira as a Project Management Tool
Jira customization
Atlassian Certified JIRA Administrator certificate
Large Scale JIRA Administration
Jira Basic Concepts
Atlassian Certified JIRA Administrator
Enterprise workshops agile concepts jira green hopper atlassian deck
JIRA Introduction | JIRA Tutorial | Atlassian JIRA Training | H2kinfosys
JIRA System Admin Traning
Agile Project and Portfolio Management Using Jira - AgileSolutions
Adapting JIRA For Scrum
Jira fundamentals
Jira as a Tool for Test Management
Using JIRA Software for Issue Tracking
Introduction To Jira
Introduction to JIRA & Agile Project Management
Jira as a Project Management Tool
Ad

Similar to Enterprise workshops jira security and permissions management atlassian deck (20)

PDF
Denver Atlassian Community 5-minute Plugins
PDF
How to Keep your Atlassian Cloud Secure
PDF
Denver ACE October 21st 2020
PDF
Denver Atlassian Community Meeting - April 2019
PDF
Atlassian User Group NYC 092718 Event
PDF
ACE Aarhus 2025 kick-off presentation deck
PDF
Jira & Ansible: Streamlining Jira Server Administration for the Enterprise
PPTX
Matt carroll - "Security patching system packages is fun" said no-one ever
PDF
How to Build a Better JIRA Add-on
PDF
Atlassian Enterprise Confluence Webinar - April 2013
PPTX
Choose your own adventure: hacking the cybersecurity profession (BSidesCharm ...
PDF
Upgrades and Admin at Scale: How to Become a Jira Admin Champion
PDF
Ambassadors go forth...
PDF
Atlassian summit comes to you - London AUG
PDF
The Top 5 Skills Enterprise Admins Need to Know
PPT
Liferay Jira & Crowd Integration
PPT
Liferay Jira & Crowd Integration
PDF
Atlassian Jira Brochure
PDF
Denver AUG Feb 2019
PPTX
JCNC2013 Case Aktia Joakim Sandström
Denver Atlassian Community 5-minute Plugins
How to Keep your Atlassian Cloud Secure
Denver ACE October 21st 2020
Denver Atlassian Community Meeting - April 2019
Atlassian User Group NYC 092718 Event
ACE Aarhus 2025 kick-off presentation deck
Jira & Ansible: Streamlining Jira Server Administration for the Enterprise
Matt carroll - "Security patching system packages is fun" said no-one ever
How to Build a Better JIRA Add-on
Atlassian Enterprise Confluence Webinar - April 2013
Choose your own adventure: hacking the cybersecurity profession (BSidesCharm ...
Upgrades and Admin at Scale: How to Become a Jira Admin Champion
Ambassadors go forth...
Atlassian summit comes to you - London AUG
The Top 5 Skills Enterprise Admins Need to Know
Liferay Jira & Crowd Integration
Liferay Jira & Crowd Integration
Atlassian Jira Brochure
Denver AUG Feb 2019
JCNC2013 Case Aktia Joakim Sandström

More from Atlassian (20)

PPTX
International Women's Day 2020
PDF
10 emerging trends that will unbreak your workplace in 2020
PDF
Forge App Showcase
PDF
Let's Build an Editor Macro with Forge UI
PDF
Meet the Forge Runtime
PDF
Forge UI: A New Way to Customize the Atlassian User Experience
PDF
Take Action with Forge Triggers
PDF
Observability and Troubleshooting in Forge
PDF
Trusted by Default: The Forge Security & Privacy Model
PDF
Designing Forge UI: A Story of Designing an App UI System
PDF
Forge: Under the Hood
PDF
Access to User Activities - Activity Platform APIs
PDF
Design Your Next App with the Atlassian Vendor Sketch Plugin
PDF
Tear Up Your Roadmap and Get Out of the Building
PDF
Nailing Measurement: a Framework for Measuring Metrics that Matter
PDF
Building Apps With Color Blind Users in Mind
PDF
Creating Inclusive Experiences: Balancing Personality and Accessibility in UX...
PDF
Beyond Diversity: A Guide to Building Balanced Teams
PDF
The Road(map) to Las Vegas - The Story of an Emerging Self-Managed Team
PDF
Building Apps With Enterprise in Mind
International Women's Day 2020
10 emerging trends that will unbreak your workplace in 2020
Forge App Showcase
Let's Build an Editor Macro with Forge UI
Meet the Forge Runtime
Forge UI: A New Way to Customize the Atlassian User Experience
Take Action with Forge Triggers
Observability and Troubleshooting in Forge
Trusted by Default: The Forge Security & Privacy Model
Designing Forge UI: A Story of Designing an App UI System
Forge: Under the Hood
Access to User Activities - Activity Platform APIs
Design Your Next App with the Atlassian Vendor Sketch Plugin
Tear Up Your Roadmap and Get Out of the Building
Nailing Measurement: a Framework for Measuring Metrics that Matter
Building Apps With Color Blind Users in Mind
Creating Inclusive Experiences: Balancing Personality and Accessibility in UX...
Beyond Diversity: A Guide to Building Balanced Teams
The Road(map) to Las Vegas - The Story of an Emerging Self-Managed Team
Building Apps With Enterprise in Mind

Recently uploaded (20)

PDF
STKI Israel Market Study 2025 version august
PDF
A contest of sentiment analysis: k-nearest neighbor versus neural network
PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PPTX
observCloud-Native Containerability and monitoring.pptx
PPTX
Web Crawler for Trend Tracking Gen Z Insights.pptx
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
CloudStack 4.21: First Look Webinar slides
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PDF
Getting started with AI Agents and Multi-Agent Systems
PPTX
Benefits of Physical activity for teenagers.pptx
PDF
WOOl fibre morphology and structure.pdf for textiles
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PPT
Module 1.ppt Iot fundamentals and Architecture
PPTX
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
PDF
August Patch Tuesday
PDF
Unlock new opportunities with location data.pdf
STKI Israel Market Study 2025 version august
A contest of sentiment analysis: k-nearest neighbor versus neural network
DP Operators-handbook-extract for the Mautical Institute
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
observCloud-Native Containerability and monitoring.pptx
Web Crawler for Trend Tracking Gen Z Insights.pptx
Assigned Numbers - 2025 - Bluetooth® Document
NewMind AI Weekly Chronicles – August ’25 Week III
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
CloudStack 4.21: First Look Webinar slides
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
Getting started with AI Agents and Multi-Agent Systems
Benefits of Physical activity for teenagers.pptx
WOOl fibre morphology and structure.pdf for textiles
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
Module 1.ppt Iot fundamentals and Architecture
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
August Patch Tuesday
Unlock new opportunities with location data.pdf

Enterprise workshops jira security and permissions management atlassian deck