Hi all,
I built a brand new Confluence server and follows the instructions here for installing an SSL wildcard cert:
https://confluence.atlassian.com/kb/how-to-import-an-existing-ssl-certificate-for-use-in-tomcat-838412853.html
In step 2, I cannot figure out what they are referring to when they specify the "<tomcatkeystorefile>". I have no idea where this is and no Google search is providing any guidance. Could anyone help me figure this one out? Everything else has been pretty straightfoward.
Thanks,
Ryan
Hi Ryan,
This is where you would list the path to the location of the keystore in Tomcat.
For more information on that, have a look at Running Confluence Over SSL or HTTPS > Step 3. Specify the location of your certificate:
By default, Tomcat expects the keystore file to be named .keystore and to be located in the user home directory under which Tomcat is running (which may or may not be the same as your own home directory). This means that, by default, Tomcat will look for your SSL certificates in the following location:
.keystore
On Windows: C:\users\#CURRENT_USER#\.keystore
C:\users\#CURRENT_USER#\.keystore
On OS X and UNIX-based systems: ~/.keystore
~/.keystore
Hi Shannon,
Thank you for the quick response. I did read that and that's what I'm trying to understand. When I look there, I don't see the .keystore file. I'm installing a wildcard SSL cert and following these directions:
In step 2 I'm supposed to merge the tomcat keystore and the one I created in step 1. However, the tomcat keystore does not exist in the location you specified under any user. Am I missing something else?
The other thing that may or may not matter is that after following through step 3 on the guide you posted, the service is listening on port 8443. I can telnet to it to confirm. However, I cannot pull up the web page with https on port 8443. I can only pull it up with http on port 8090.
Just to rule variables out. I tried to install the self-signed certificate exactly as the directions show and I'm having the same issue where a service is listening on port 8443 but I can't pull up the webpage on it.
It's so much easier to set up a reverse proxy server ahead of Confluence and manage SSL on the proxy. Atlassian has docs for apache, nginx (same procedure for Confluence) and IIS.
Any of these proxy servers have the smarts to start up as a privileged user and bind to port 443, then spawn child processes as an unprivileged user. This allows you to run Confluence as an unprivileged user and bind to 8090. This is far better from a security standpoint. It is also much easier to manage SSL certificates on any of these proxy servers than it is dealing with keytool and Java keystores. You can avoid having to restart Confluence when you update your certificates as well. They can also handle http -> https redirection so you can tell your users to point their browser to http://confluence.domain.com and they will be redirected to https automagically.
This may be an option if I have to do it. I don't really want to have to run two servers to do it though. If I can keep it all confined to one, that would be ideal. What are the security advantages?
There is no need to run the proxy on a separate server. You can run it on the Confluence server. We commonly set Confluence up this way and configure it to connect to 127.0.0.1:8090. The biggest advantage is simple cert management. You can also do cool stuff like displaying a custom “system down” page when you perform maintenance or unexpected go down. From a security perspective, if an attacker is able to exploit a vulnerability in Java that allows them to execute arbitrary code, that code will be executed as the “confluence” user. This is an unprivileged user, so I can’t do things like reboot, access other users data, etc. it limits your exposure in the event of a hack.
ohhh, i think i understand. so i could install apache on the confluence server and then run the proxy from there. i've managed apache servers for many years but this is my first time working with tomcat, and really my first time getting my hands real dirty with certs. i usually fumble through them well enough.
so i setup apache and setup my certs and redirects from that?
It looks like you're new here. Sign in or register to get started.