my SSL certificate expired in Bitbukect. How I update new certificate with it?
Dear Thusitha,
What version of Bitbucket instance do you have this request for ?
Regards,
Victor.
Version 4.11 under tomcat and I already got .crt and cer.pem files from godady. I need to know how to remove current key and how to install new key to it?
SSL Certificate in TOMCAT through godaddy.com
1. Import the gd_bundle certificate using the following command: (Replace the file location with the location you placed your new certificates from GoDaddy)keytool -import -alias intermed -keystore tomcat.keystore -trustcacerts -file gd_bundle.crt
2. Import your certificate signed by GoDaddy by typing the following command: (Replace myFQDN.crt with the file name and location of the new GoDaddy certificate)keytool -import -alias tomcat -keystore tomcat.keystore -trustcacerts -file myFQDN.crt
3. change the connector from the server.xml file.< Connector port="443" protocol="HTTP/1.1" SSLEnabled="true"maxThreads="150" scheme="https" secure="true" clientAuth="false" sslProtocol="TLS"keystoreFile="path of tomcat.keystore file" keystorePass="your password" / >
After you save changes to server.xml, restart Tomcat to begin using your SSL.
You might want to carefully read through Securing Bitbucket Server with Tomcat using SSL.
If you need specific information, feel free to ask.
Hi Thanks for rely. I got following error after restart with new settings
uses an unsupported protocol.
ERR_SSL_VERSION_OR_CIPHER_MISMATCH
DETAILS
Unsupported protocolThe client and server don't support a common SSL protocol version or cipher suite.
I run following commands in certificate file location
keytool -import -alias intermed -keystore mesp2018.jks -trustcacerts -file 2018gd_bundle-g2-g1.crtkeytool -import -alias tomcat -keystore mesp2018.jks -trustcacerts -file 2018.crtiserver xml as follows<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol"maxThreads="150" SSLEnabled="true" scheme="https" secure="true"keystoreFile="/etc/pki/tls/SSL/mesp2018.jks" keystorePass="********"clientAuth="false" sslProtocol="TLS" />
Please assist.
It looks like you're new here. Sign in or register to get started.