Hi all,
I am lost on this one. We needed to update our SSL certificates so I got a new cert/pem from Comodo and updated Jira's user is with the new .keystore. Jira comes up and has a valid license that works just fine. Same for confluence
However, the application links between the two no longer work. When I did this same thing 2 years ago I had no problem with the application links afterward.
Also Just playing around with Curl from confluence to confluence I get this:
[root@confluence ~]# curl -v https://confluence.verdasys.com:8443/
* About to connect() to confluence.verdasys.com port 8443 (#0)
* Trying <ip removed for security>...
* Connected to confluence.verdasys.com (ip removed) port 8443 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
* CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none
* Server certificate:
* subject: CN=*.verdasys.com,OU=PremiumSSL Wildcard,OU=C Information Technology,O="DIGITAL GUARDIAN, INC.",STREET="860 Winte r Street, Suite 3",L=Waltham,ST=MA,postalCode=02451,C=US
* start date: Jan 18 00:00:00 2018 GMT
* expire date: Feb 20 23:59:59 2020 GMT
* common name: *.verdasys.com
* issuer: CN=COMODO RSA Organization Validation Secure Server CA,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB
* NSS error -8179 (SEC_ERROR_UNKNOWN_ISSUER)
* Peer's Certificate issuer is not recognized.
* Closing connection 0
curl: (60) Peer's Certificate issuer is not recognized.
More details here: http://curl.haxx.se/docs/sslcerts.html
curl performs SSL certificate verification by default, using a "bundle"
of Certificate Authority (CA) public keys (CA certs). If the default
bundle file isn't adequate, you can specify an alternate file
using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
the bundle, the certificate verification probably failed due to a
problem with the certificate (it might be expired, or the name might
not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
the -k (or --insecure) option.
saying both it knows the issuers is COMODO and that the issuer is unrecognized?
Thanks,
Robert