I need to upgrade confluence 5.3.4 to deal with the recently announced security problems with webdav and web connector. What is the latest version I can upgrade to directly from 5.3.4.
Do I need to upgrade Jira at the same time?
Hey @Eugene Chu ,
As Petr mentioned, the plugin compatibility checker is a very helpful tool as it will check all your installed plugins for compatibility with newer versions of Confluence by fetching their most recent version information from Marketplace. It is accessible from the admin panel:
More info on the compatibility checker is here if you're interested in reading up.
Cheers and best wishes for your upgrade,Daniel
Hi,
as you can see in documentation (https://confluence.atlassian.com/doc/upgrading-confluence-4578.html#UpgradingConfluence-Planyourupgrade) you can upgrade to latest version (if you have valid maintenance), but be carefull regarding plugins.
First check compatibility with UPM (CONFLUENCE-DOMAIN/plugins/servlet/upm/check?source=manage) if therr will be some incompatible plugin for latest version try one version before or something like that or check Atlassian Marketplace if plugin is still in development.
Then take backup and try it in test environment. If everything will be ok on test then upgrade your production.
You don't need upgrade Jira in same time, but why don't do it. :-)
Thank you Petr for your answer. I'm not sure how to do this check:
"CONFLUENCE-DOMAIN/plugins/servlet/upm/check?source=manage"
Is that from the confluence administration console?
I am running a couple of add-ons:
So I will have to check with their authors to see if their plugins will work in the latest version of confluence.
Sorry for the late response, but we are handling an incident with our instrument on the ISS, and I may not be able to devote my full attention to this update for a few days.
Eugene Chu
Thank you Danial, Petr,
I have copied my Confluence installation onto another host and was able to bring it up, sort of. I need to get my users onto this server instance so they can check it out, but I can not log into it with anyone other than the local admin account I had set up.
I checked the LDAP settings (under User Directories -> which I had been using on the original server, and there were no errors from the copy. But when I try to test the LDAP connection, I get:
LDAP_SERVER:636 nested exception is javax.naming.CommunicationException: LDAP_SERVER:636 [Root exception is javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
I thought maybe this was caused by my copying the host SSL certs and keys from the old server, so I generated new versions for this new host, but that did not help.
I tried various solutions on the Atlassian web site that addressed the above error messages, but they did not help either. So now, I seek assistance from those with more experience.
We typically see this error when your LDAP servers / domain controllers are using self-signed certs or certificates issued by a provider like GoDaddy which may not be in the Java trust store.
The fastest way to address this (so you don't have to change things on the LDAP server side) is to import the certificate into the trust store in the Java that Confluence is using to run. We've got an article explaining how to do that here for various operating systems.
Thank you Daniel,
The new host references its Java truststore in /etc/pki/java/cacerts, and that was one of the things I tried; updating it with the new self-signed certs I got from our institutional cert server. That did not help. In addition to the PKIX error messages, I'm also getting these from the LDAP test function:
Test user rename is configured and tracked : Not performed
Test get user's memberships : Not performed
Test retrieve group : Not performed
Test get group members : Not performed
Test user can authenticate : Not performed
Maybe they're all just a result of not being able to connect to our LDAP server.
It looks like you're new here. Sign in or register to get started.