We have a server for which we are running JIRA 7.04 using start/stop script (not as a service) and that we also use LDAP directory service in order to allow our client users to log onto JIRA dashboard for which they use JIRA to submit forms. Currently we have lots of users that are not able to access the JIRA Service Desk URL/System dashboard and that the get LDAP errors like of "Error occurred while trying to authenticate user 'jared.noel@vnsny.org')" as shown below:
2019-05-23 11:20:42,239 http-nio-8080-exec-39 ERROR anonymous 680x11937x1 oec13g 65.51.234.2,10.154.71.241 /servicedesk/customer/user/login [c.a.c.manager.application.ApplicationServiceGeneric] Directory 'VNSNY AD' is not functional during authentication of 'jared.noel@vnsny.org'. Skipped.
2019-05-23 11:20:42,239 http-nio-8080-exec-39 ERROR anonymous 680x11937x1 oec13g 65.51.234.2,10.154.71.241 /servicedesk/customer/user/login [c.a.j.security.login.JiraSeraphAuthenticator] Error occurred while trying to authenticate user 'jared.noel@vnsny.org'.
com.atlassian.crowd.exception.runtime.OperationFailedException
---
019-05-23 11:20:33,789 http-nio-8080-exec-26 ERROR anonymous 680x11928x1 1cv40f4 65.51.234.100,10.154.71.241 /servicedesk/customer/user/login [c.a.c.manager.application.ApplicationServiceGeneric] Directory 'VNSNY AD' is not functional during authentication of '59440@vnsny.org'. Skipped.
2019-05-23 11:20:33,790 http-nio-8080-exec-26 ERROR anonymous 680x11928x1 1cv40f4 65.51.234.100,10.154.71.241 /servicedesk/customer/user/login [c.a.j.security.login.JiraSeraphAuthenticator] Error occurred while trying to authenticate user '59440@vnsny.org'.
2019-05-23 19:41:25,903 Caesium-1-2 INFO ServiceRunner [c.a.crowd.directory.DbCachingRemoteDirectory] failed synchronisation complete for directory [ 10200 ] in [ 175ms ]
2019-05-23 19:41:25,940 Caesium-1-2 ERROR ServiceRunner [c.atlassian.scheduler.JobRunnerResponse] Unable to synchronise directory
We have tried to tried to modify some of the options for the affected User Directory (i.e. VNSNY AD) in JIRA Administration/User Directory control panel but have not been successful in getting the issue resolved. the hostname for that affected User Directory of "VNSNY AD" is adldap.vnsny.org which is a VM/system that is on the client's side/network. when we do a dig command for that VM from the JIRA server it shows that the SOA authority for that server (i.e. ) is ns-217.awsdns-27.com, see below:
# dig adldap.vnsny.org
; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.37.rc1.el6_7.7 <<>> adldap.vnsny.org
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 7713
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION:
;adldap.vnsny.org. IN A
;; AUTHORITY SECTION:
vnsny.org. 1800 IN SOA ns-217.awsdns-27.com. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 86400
;; Query time: 7 msec
;; SERVER: 10.255.255.11#53(10.255.255.11)
We have thought that the SSL certificate for the JIRA might have been a culprit for this problem and that since JIRA server is also incorporating a Tomcat server for its operation and since the Tomcat uses JAVA Key-store file for storing its certificates therefore, we need to know where exactly that keystore file is located (our Jira base installation directory is '/apps/atlassian-install' ) and how we can make sure that the installed certificate file is NOT expired. Also another question is if the LDAP server as configured on the User directory control panel, i.e. adldap.vnsny.org should get/receive its SOA information from Amazon (i.e . ns-217.awsdns-27.com. awsdns-hostmaster.amazon.com)? Please treat this issue with a very high urgency as this issue is affecting a large number of the JIRA Service Desk application users. Please feel free to contact me on my Cell# 512-228-7042 or via my Email as :Roozbeh.Adhami@ipsfot.com. We really really in a tight situation.
Best Regards,
RRoozbeh Adhami
Senior Application Support Engineer
IPsoft Inc.