Thanks for clarifying. I don't think this gonna help though, really. You also need to generate the key and provide the path to the key and keystore password. So if you automate those steps in the SPEC file, then it would totally make sense to add such an option, because it will just work.
FYI, I used the following commands (generates a self-signed certificate valid for the next 10 years):
keytool -genkey -keyalg RSA -alias selfsigned -keystore /var/lib/jenkins/ssl/keystore.jks -validity 3650 -dname "cn=FQDN" -storepass XXX
The FQDN can be determined via
The command to use HTTPS is
--httpsPort=443 --httpsKeyStore=/var/lib/jenkins/ssl/keystore.jks --httpsKeyStorePassword=XXX
Also it would make sense to add an option to disable AJP port:
If you will make a working patch, I can try to help to make a pull request, unless you can also do it yourself.
What is your suggestion more specifically? You can easily change flags in /etc/sysconfig/jenkins to use https instead of http... What can be easier?