Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Next challenges

Recent achievements

  • Global
  • Personal

Recognition

  • Give kudos
  • Received
  • Given

Leaderboard

  • Global

Trophy case

Kudos (beta program)

Kudos logo

You've been invited into the Kudos (beta program) private group. Chat with others in the program, or give feedback to Atlassian.

View group

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Redhat openjdk 1.8.0.272.b10-1 breaks tls in bamboo 7.1

We've been using bamboo with tls on port 8443 for years.  Redhat released openjdk 1.8.0.272.b10-1.el7_9 and when we upgraded our bamboo server to it, none of the agents or browsers could communicate to 8443.  We are seeing a "err_ssl_protocol_error" message in chrome and the agents report "javax.net.ssl.sslexception: unsupported or unrecognized ssl message" in their logs.  We do have a proxy in front on port 443 that proxies to 8443 and that still works fine.

I've tried modifying java.security file settings but nothing seems to be making a difference.  My concern is that I'm going to see the same issue with our other Atlassian servers.

Also, I upgraded to bamboo 7.1.4 but forgot to specify the bamboo.home directory in atlassian-bamboo/WEB-INF/classes/bamboo-init.properties.  When I went to the bamboo server on port 8443, it displayed the web page showing me the diagnostic page that shows the java version check and the bamboo.home setting and how to fix it so the tls issue happens after I specified the bamboo.home directory.

Had anyone else seen issues with upgrading to that version of openjdk on RHEL7?

Thanks

2 answers

1 accepted

3 votes
Answer accepted

Hi @doug_curtis,

It looks like you have stumbled onto this bug.

Glad to see that you managed to fix it by downgrading Java. If this was not an option, I was going to suggest the workaround proposed by my colleague in the bug report above.

Good news is that this has been fixed in Bamboo 7.2.0 already (that is yet to be released as of today).

Cheers,
Jey

Thanks for this.  This seems exactly like what I'm running into.  I'll play around with options specified in the bug report to verify.

Thanks again!

That's definitely what it was.  Disabling the RSASSA-PSS signature algorithm fixed the issue.  At least now if I HAVE to upgrade to u272, I have a solution for it.

Thanks for the quick response.

Jeremy Owen Atlassian Team Nov 19, 2020

G'day Doug,

We're fairly confident you won't run into this with any other Atlassian products as it relates to a certain Bamboo dependency and how it's loading crypto providers. 

Cheers,

Jeremy

That's good news.  I was going to add RSASSA-PSS on my other Atlassian servers as a precautionary measure but I'm glad that it's probably not necessary.

0 votes
edwin Community Leader Nov 19, 2020

Hi @doug_curtis ,

Please confirm and test the following.

  1. Custom configurations were migrated from the previous installation.
  2. Port 8443 is enabled in the server.xml .... Bamboo listens on 8085 by default.
  3. Unrecognized SSL message, plaintext connection? 

1.  Yes they were.  I only upgraded from 7.1.1 to 7.1.4 to see if it fixed the issue.  The only upgrade that broke bamboo was the openjdk upgrade.

2.  Yes.  We have a connector specified in the server.xml for port 8443 that references a keystore with the password.  This worked fine before the openjdk upgrade.

3.  I saw this in my searches and tried it but it didn't fix the issue.

 

I should also note that downgrading openjdk fixes the issue.  We don't run any custom jdk settings.  I've only started trying different jdk settings to see if it affects it.  It seems like either a TLS protocol or cipher issue.

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Bamboo

Bamboo 7.1 is here and is packed with value!

I'm happy to announce that Bamboo 7.1 has been released and it’s overflowing with awesome new features. Top-voted issues First and foremost, a bunch of JAC top voted issues has been delivered - y...

943 views 4 7
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you