I'm trying to upgrade our Confluence install from 6.6 to 7.4. This generally works, and the HTTP site starts without any issue, but after the upgrade we can't connect to Confluence over HTTPS anymore. If we try, we get an SSL cypher error. In Firefox that is SSL_ERROR_NO_CYPHER_OVERLAP, but Chrome and IE11 display similar errors about not allowing the connection because of insufficient SSL settings.
If I query the HTTPS server with nmap I get the following list of offered cyphers:
| ssl-enum-ciphers:
| TLSv1.2:
| ciphers:
| TLS_DHE_DSS_WITH_AES_128_CBC_SHA (dh 1024) - A
| TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 (dh 1024) - A
| TLS_DHE_DSS_WITH_AES_128_GCM_SHA256 (dh 1024) - A
| TLS_DHE_DSS_WITH_AES_256_CBC_SHA (dh 1024) - A
| TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 (dh 1024) - A
| TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 (dh 1024) - A
| compressors:
| NULL
| cipher preference: client
| warnings:
| Key exchange (dh 1024) of lower strength than certificate key
|_ least strength: A
Which really seems woefully inadequate. If I query one of our IIS Webservers that is using the same certificate I get a lot more results including modern cyphers like:
| TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (secp384r1) - A
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (ecdh_x25519) - A
| TLS_RSA_WITH_AES_256_GCM_SHA384 (rsa 2048) - A
I have tried a few solutions that come up when searching for this issue, such as converting the keystore between PKCS12 and JKS, adding a "ciphers" parameter to the HTTPS connector and adding a keystoreType parameter to the connector. But none of them help.