I am setting up Jira on a CentOS 7 EC2 instance in AWS using RDS (5.7 with TLS) as the backend database.
The installer failed with the following error:
This MySQL instance is not properly configured. Please follow the documentation for MySQL 5.7 setup.
I have added the Amazon RDS CA Cert into the jira keystore using the following command:
/opt/atlassian/jira/jre/bin/keytool -import -alias mysqlclientcertificate -keystore /opt/atlassian/jira/jre/lib/security/cacerts -file rds-ca-2019-root.pem
catalina.out reports the following still:
Mon Sep 21 11:27:24 PDT 2020 WARN: Establishing SSL connection without server's identity verification is not recommended. According to MySQL 5.5.45+, 5.6.26+ and 5.7.6+ requirements SSL connection must be established by default if explicit option isn't set. For compliance with existing applications not using SSL the verifyServerCertificate property is set to 'false'. You need either to explicitly disable SSL by setting useSSL=false, or set useSSL=true and provide truststore for server certificate verification.
Can someone from Atlassian help with the following:
- How to solve my current problem during installation
- I understand you can fix this post install by editing dbconfig.xml. However that doesn't help at all during the installation process and the install wizard is very limited in both error reporting and specifying options to fix this easily. Please don't tell me I need to start with an embedded DB and then migrate in order to fix this.
Bonus points for:
- Tomcat communicating on port 80 and 443 without a proxy or iptables forwarding
- Official documentation on setting up jira in AWS with EC2 and RDS (with TLS). This is a pretty common setup and I'm surprised there isn't official documentation on this.