I am setting up Confluence Datacenter using the latest version of java and am having issues connecting to ldaps, verified that i could connect to ldap unsecured. Error is the following:
ldap.server.com:636; nested exception is javax.naming.CommunicationException: ldap.server.com:636 [Root exception is javax.net.ssl.SSLHandshakeException: java.security.cert.CertificateException: No subject alternative DNS name matching ldap.server.com found.]
Could be as a result of LDAPS being more robust in this new version of java, not sure how to fix this.
Change to LDAPS: https://www.oracle.com/technetwork/java/javase/8u181-relnotes-4479407.html#JDK-8200666
Thanks,
Hamzah Mirza
Hi Hamzah,
Welcome to the community. It sounds like this is a network configuration error for the LDAP host itself. You might need to add a record to the /etc/hosts file which maps the domain name of the LDAP server to its IP address.
All the best,Cameron
Our ldap servers are a large cluster environment. I don't believe i would have to add it to the /etc/hosts file as the connection to ldap unsecure is being made so servers are reachable.
As a side note, our jira setup had a similar issue but was fixed by us adding
-Dcom.sun.jndi.ldap.object.disableEndpointIdentification=true"
to /opt/atlassian/jira/bin/setenv.sh JAVA_OPTS. This fix did not work with confluence.
@Hamzah Mirzait seems you're having a similar issue to this: https://jira.atlassian.com/browse/CONFSERVER-38853
This looks promising. looks like there are 2 fixes from issue https://jira.atlassian.com/browse/CONFSERVER-39309.
I wont disable ssl, but the first option says to add the jvm argument
-Djdk.tls.trustNameService=true
where would i add this in the setenv.sh?
Hi ,
please try the below in setenv.sh.
JAVA_OPTS="$JAVA_OPTS -Dcom.sun.jndi.ldap.object.disableEndpointIdentification=true"
it works for me in confluence 5.10.2 data centre version.
It looks like you're new here. Sign in or register to get started.