I am using:
Red Hat 7.5
Postgres 9.6
Atlassian Service Desk 7.10.2
I have followed postgres's guide to setting up SSL: https://www.postgresql.org/docs/9.6/static/ssl-tcp.html
This works perfectly on my confluence server (Confluence uses jdbc connector to connect over ssl to postgres 9.6), but on my Service Desk server when I add: ssl=true to: /var/atlassian/application-data/jira/dbconfig.xml
<url>jdbc:postgresql://XXX.XXX.XXX.XXX:5432/servicedesk?ssl=true</url>
I recieve this error: >LOG: could not accept SSL connection: sslv3 alert certificate unknown
when I go to the Service Desk website I see an error indicating:
Database: JIRA couldn't connect to your database
JIRA failed to establish a connection to your database.
This could be because:
- Your database isn't running
- The configuration of your dbconfig.xml file is incorrect (user, password, or database URL etc.)
- There is a network issue between JIRA and your database (e.g. firewall, database doesn't allow remote access etc.)
There are several other solutions you can try, review our documentation and see what works for you.
Learn more
If I add this: sslfactory=org.postgresql.ssl.NonValidatingFactory
so
<url>jdbc:postgresql://XXX.XXX.XXX.XXX:5432/servicedesk?ssl=true&sslfactory=org.postgresql.ssl.NonValidatingFactory</url>
when I go to the Service Desk website (which is https and the SSL on the HTTPS works just fine) I am presented with the initial setup menu (https://XXX.XXX.XXX.XXX:8443/secure/SetupMode!default.jspa)
My pg_hba.conf file is set to allow:
hostssl all all 0.0.0.0/0 md5
I have tried
hostssl db db_user 0.0.0.0/0 md5
hostssl db db_user 0.0.0.0/0 cert
hostssl db db_user 0.0.0.0/0 cert clientcert=1
All of my certs (Intermediate, root, and server) are loaded into the java keystore and placed in the correct location for postgres
My database (and db user) matches the CN of my cert for the Service Desk server.
If anyone has any suggestions I would appreciate it.