Hello all,
we have read and implemented
Running Confluence Over SSL or HTTPS from:
https://confluence.atlassian.com/doc/running-confluence-over-ssl-or-https-161203.html
We are running jira and confluence on 1 VM with 2 NICs:
ens192: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 10.10.1.13 netmask 255.255.255.0 broadcast 10.10.1.255
ether 00:0c:29:e7:b7:71 txqueuelen 1000 (Ethernet)
RX packets 1381613 bytes 362204221 (345.4 MiB)
RX errors 0 dropped 11 overruns 0 frame 0
TX packets 1812036 bytes 313669051 (299.1 MiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
ens192:0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 10.10.1.10 netmask 255.255.255.0 broadcast 10.10.1.255
ether 00:0c:29:e7:b7:71 txqueuelen 1000 (Ethernet)
lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536
inet 127.0.0.1 netmask 255.0.0.0
loop txqueuelen 1000 (Local Loopback)
RX packets 4413 bytes 707965 (691.3 KiB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 4413 bytes 707965 (691.3 KiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
virbr0: flags=4099<UP,BROADCAST,MULTICAST> mtu 1500
inet 192.168.122.1 netmask 255.255.255.0 broadcast 192.168.122.255
ether 52:54:00:9a:d4:5d txqueuelen 1000 (Ethernet)
RX packets 0 bytes 0 (0.0 
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 0 bytes 0 (0.0 
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
Jira is running fine (over ssl) on address 10.10.1.13, but when we try to access confluence on 10.10.1.10, the tomcat is using jiras security certificate.
We have correctly set DNS entries for jira and for confluence:
[root@jira logs]# nslookup jira.git
Server: 10.10.1.1
Address: 10.10.1.1#53
Non-authoritative answer:
Name: jira.git
Address: 10.10.1.13
[root@jira logs]# nslookup confluence.git
Server: 10.10.1.1
Address: 10.10.1.1#53
Non-authoritative answer:
Name: confluence.git
Address: 10.10.1.10
We have implemented firewalld rules that allow ports 8080 and 8443 (for jira) and 8090 and 8443 (for confluence). We have also implemented port forwarding on firewalld from port 80 to port 8080 and, respectively, 443 to 8443 for both zones:
[root@jira logs]# firewall-cmd --zone=public --list-all
public (active)
target: default
icmp-block-inversion: no
interfaces: ens192
sources:
services: cockpit dhcpv6-client http https ssh
ports: 8080/tcp 8081/tcp 8443/tcp
protocols:
masquerade: yes
forward-ports: port=80:proto=tcp:toport=8080:toaddr=
port=443:proto=tcp:toport=8443:toaddr=
source-ports:
icmp-blocks:
rich rules:
[root@jira logs]# firewall-cmd --zone=work --list-all
work (active)
target: default
icmp-block-inversion: no
interfaces: ens192:0
sources:
services: cockpit dhcpv6-client ssh
ports: 8090/tcp 8443/tcp
protocols:
masquerade: yes
forward-ports: port=80:proto=tcp:toport=8090:toaddr=
port=443:proto=tcp:toport=8443:toaddr=
source-ports:
icmp-blocks:
rich rules:
We have issued SSL certificates for both jira (running on 10.10.1.13) and confluence (running on 10.10.1.10) by our internal authority.
The current behavior is that when we are trying to reach confluence on https://confluence.git, we are getting the certificate from jira. The message is that the certificate was issued for a different hostname/IP and when we look into the certificate, it really tells the browser that it is for jira IP address and DNS entry.
Has anyone seen this before? What are we doing wrong?
Please let me know if you need any more specific details.