Please provide DETAILED and VERBOSE instructions on how to implement SSL/HTTPS on an on-prem Confluence server using an existing .pfx certificate produced by MS cert services. Your article here:
https://confluence.atlassian.com/doc/running-confluence-over-ssl-or-https-161203.html
...is woefully inadequate and incomplete. I have tried following this article which is applicable to Jira:
https://confluence.atlassian.com/jirakb/how-to-run-jira-over-https-with-a-personal-information-exchange-pfx-certificate-432804342.html
...but it does not work in Confluence. This information should be published. Using MS certificate services is very common in your average med or larger sized business. Not addressing it is a shortcoming on the part of Atlassian.
So when writing documentation - precision matters. It appears that the Atlassian provided documentation lacks some of it. So here are the steps they miss. Because I value the time of others, I'm going to keep it brief - but precise. A pic is worth 1000 words.
1. put the .pfx file somewhere on the server (your choice) For this example I created a folder on the root of C:\
2. adjust the permission on the folder containing the pfx file. The average user in the "users" group will have at least read permission by default in almost all cases and they shouldn't. Adjust permissions to suit your use case. Confluence runs as a network service so I removed the users group and added [network service] granting it read access.
3. use the keytool located at: C:\Program Files\Atlassian\Confluence\jre\bin to get the alias name of cert cert. This will be a GIUD. (Atlassian's info is incomplete here). You need to use this actual value later. It's what is covered in green.
Here is what that looks like:
Names omitted to protect the innocent. The GREEN part of the output is what you'll need. Copy that into notepad.
4. Head over to C:\Program Files\Atlassian\Confluence\conf and open Server.xml in a text editor. Uncomment the SSL connector section... There's some info you'll need to add.. This is also incomplete in Atlassian's documentation. You will need to add:
keystoreFile="C:\ConfluenceCerts\cert.pfx"
keystorePass="YourSuperSecretPasswordGoesHere"
keyAlias="your alias retrieved from the keytool above"
keystoreType="PKCS12"
What that looks like. Make sure the keystorePass and keyAlias values are enclosed in "quotation marks". You can't see that in my screenshot below:
Bounce the Confluence service and try it. This should be in a detailed document specific to Confluence on Atlassian's site.
1. Do you have a trusted certificate for your confluence server? Is the existing pfx file created for the Confluence domain?
2. If 1. Yes, then save this file on the Confluence server
3. The file <install-directory> /conf/server.xml edit according to the Confluence instructions for SSL / HTTPS (Step 2).
4. Since the file is in PKCS12 format, make the following entry in the server.xml:keystoreType="PKCS12"
5. Then continue to work through the Confluence instructionshttps://confluence.atlassian.com/doc/running-confluence-over-ssl-or-https-161203.html
Both of those documents have worked fine for me, many times, whatever the certificate source. (There were some additional pain points caused by MS ignoring standards as per tradition, but they seem to have stopped that early last year)
I think you need to give us more detail on where they are going wrong, and what you are doing differently to what the docs say.
Little advice, make yourself a Confluence page with the steps shown here.Otherwise you will start again with the next update!
It looks like you're new here. Sign in or register to get started.