Can SSL certificate for JIRA expire?

Hi all,

Our AD users lost access to JIRA. It happened just abruptly.

Because we a had a working connection JIRA <-> AD.

Long ago we tuned such integration through our home made certificate using "./keytool -import" and it worked.

Yesterday I found out that "ldap.secure" parameter set to "true" I changed it to "false", restarted JIRA but still no access for AD users. 


Log:

Caused by: org.springframework.transaction.CannotCreateTransactionException: Could not create DirContext instance for transaction; nested exception is org.springframework.ldap.CommunicationException: <server name>; nested exception is javax.naming.CommunicationException: <server name>:636 [Root exception is javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target] 

So can SSL certificate expire?

And what else can be done to fix it?

Thank you. 

2 answers

1 accepted

This widget could not be displayed.

Yes, SSL certificates expire.

You need to create a new one and import it to Jira, just as you did with the old one. 

David Currie Atlassian Team Jul 06, 2015

Also the certificates are stored in the trust store, which is typically cacerts located in a subdirectory the Java home directory. If you make any changes to Java, such as upgrading it, this can overwrite that trust store and you need to re-import the certs.

Better yet, import the CA certificate(s) that sign the LDAP server's certificate.

This widget could not be displayed.

Thank you all, chaps

A newly generated certificate sorted that out. 

Suggest an answer

Log in or Sign up to answer
Atlassian Summit 2018

Meet the community IRL

Atlassian Summit is an excellent opportunity for in-person support, training, and networking.

Learn more
Community showcase
Published yesterday in Marketplace Apps

The 7 hacks of highly successful automation

...there's anything I've learnt from working, it's that people are lazy! No offense to anyone reading this, but it's true and we can all admit it. The easier you make something for someone, the more...

141 views 0 9
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you