I configured my Jenkins server to only use HTTPS and enabled security.
As well I don\'t like anybody who\'s not logged on to see the Dashboard (even if it would be empty). Here
I've just started using the cctray Jenkins transport extension. Early days, but it seems to work as advertised and is connecting to our secure server perfectly happily.
Currently, the only significant limitation seems to be that if your password expires there's no way to re-enter your credentials.