ENVIRONMENT:
- OS = CentOS 7 Minimal v1806, fully updated
- JIRA Software 8.4.1
- Open Source CA (on-premise)
We have installed the base OS, CentOS 7. Our CA is on-premise, and we are the admins. We have generated a PEM Key Pair for use on the server and with JIRA. The full generated certificate includes the KEY, the Signed CERT, and the CHAIN. We break these apart into KEY.PEM, CERT.PEM, and CHAIN.PEM. Each are installed on the server for their respective use for various uses on the server, not just JIRA. The goal is to use the existing generated certificates with JIRA as well
After installing JIRA, we followed the instructions to create the JKS Keystore. This is done in JKS format.
ASSUME THE FOLLOWING:
- The Server.xml file was configured with the proper HTTPS connector for port 8443
- The firewall has port 8443 open (as well as 80/443/8080/5432
- The CA certs were installed into the JAVA_HOME cacerts keystore
- The KEY.PEM begins with -----BEGIN PRIVATE KEY..... and ends with ....END PRIVATE KEY------ Headers have been stripped out
- The Signed Cert begins with -----BEGIN CERTIFICATE..... and ends with .....END CERTIFICATE----- Headers have been stripped out
- We are not CA/PKI experts (haha!)
ATTEMPTS:
- Used keytool to try import the KEY.PEM into the Keystore - RESULT: Cannot import the KEY.PEM into the keystore
- Combined and converted the KEY.PEM and CERT.PEM into a P12 using openssl. Converted the JKS Keystore into a PKCS12 format. Used keytool to import the combined P12 into the Keystore. RESULT: This is successful in that the P12 imports into the Keystore. The HTTPS connector type was changed from JKS to PKCS12, but after restarting the server the page loads with the self-signed certificate. It loads just fine for HTTP. Looking at the contents of the JKS Keystore and it only shows the imported Cert, so not even sure where it's pulling the self-signed cert from
- Instead of generating a PEM Key Pair from the CA, we generated a P12 Key Pair directly from the CA. We did NOT break it apart into KEY/CERT/CHAIN. Used keytool to import the P12 Keystore into the JKS Keystore. RESULT: It imported fine, but the Page fails to load after a server restart. Tried setting the Connector to JKS and PKCS12 respectively, but neither made a difference
- Converted the KEY.PEM to DER format (pkcs8) RESULT: The key imports fine into the JKS Keystore, but cannot import the Signed Cert PEM into the Keystore
Here is the only way we can get it to work:
- Create a JKS Keystore
- Generate a CSR using keytool
- Submit the CSR to our CA, and sign it receiving a Cert that includes the Signed Cert and the CA CHAIN
- The above Signed Cert includes Headers (Subject: CN=.......Issuer: C=.....). We did not modify this at all
- Used keytool to import the Cert into the Keystore
- Modified the Connector for HTTPS/8443 pointing to this Keystore with JKS type
- Used keytool to import the CA Certs into the JAVA_HOME cacerts Keystore
- Reboot the Server
- The web page is accessible properly with the correct Cert and is trusted
CONCLUSION: The only way we can get this work is to use the CSR method. Without going into more detail than I already have (if you made it this far), this is not preferred. The Certs are created and installed on the Server long before JIRA (or any application) is installed on the server, and we'd like to keep this process if possible. I'm sure this is just a matter of figuring the proper way to convert the Cert into a format that the JKS will accept, but it's a little bit out of our expertise now. Anyone have any ideas on what we can do to use the original KEY.PEM, CERT.PEM, CHAIN.PEM with JIRA?