For many years I have had JIRA connected to Active Directory for read only using LDAP. As part of a global security push I've been asked to perform this over LDAPS. Fair enough.
I've imported the server's security certificate as I have done previously when setting up IMAPS. But I'm still getting the dreaded:
{code}
Connection test failed. Response from the server:
simple bind failed: myhost.mydomain:3269; nested exception is javax.naming.CommunicationException: simple bind failed: myhost.mydomain:3269 [Root exception is javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target]
{code}
Which looks like a pretty straight forward problem with my cacerts file. I've imported so i'm *pretty* sure this is fine. I'm using JIRA standalone so there is no JDK installed, just the bundled JRE. How can I debug this? Does the bundled tomcat look for a different cacerts file?
How can I verify which cacerts file is being used?