SSL certificate question Jira

Ruedi Neff October 22, 2017

Hi

I'm pretty new on Jira and Tomcat. We have to update our ssl certificate for an other year with a new COMODORS certificate. We've had a old certificate (GeoTrust) with *.domain.ch which is correct from the naming aspect but expired from the date. - Now we've falsely made one with *domain.ch without the first dot... This should be a wildchart certificate for our domain.ch. - Will this work or can this be the problem for not restarting Jira after this ssl certificate update?

We're running Jira 7.2.4 and Tomcat 8.0.33.

Thanks for your suggestions

kind regards

1 answer

1 vote
Tayyab Bashir
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
October 23, 2017

Hi, 

No, I think this will not work for you. 

*domain.ch is expecting something like:
wwwdomain.ch or abcdomain.ch 

So it will not work for www.domain.ch since its another sub-level domain. 

But your CA shouldn't issue such a certificate in the first place.
Because you can easily impersonate other domains that don't belong to you.
For e.g. foo-domain.ch etc, (which are clearly not yours)

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
October 23, 2017

I'd agree with Tayyab here, your "false" certificate is effectively invalid.

What errors are you getting on trying to start Jira?

Suggest an answer

Log in or Sign up to answer