LDAPS connection

I would like to make an SSL connection to our LDAP directory from Stash, however the certificate the LDAP server is using, is not matching the DNS registration. And it's not an option to change it, because it involves too many dependencies from other systems using LDAP.

I've found this: https://confluence.atlassian.com/display/STASHKB/No+subject+alternative+DNS+name+matching+%3CHOST_NAME.DOMAIN_NAME%3E+found.

I think it's a bad idea to change the hosts file, so I the Data approach and changed the connection to LDAPS and port 636 + set the value ldap.secure to false. It partly worked (see attached screendump of the LDAP connection).

Can I fix this by change some values in the Database ?

BTW it would be nice if Stash had a setting to disabled Host Name validation. I've seen it done in other Java applications ;-)

4 answers

This widget could not be displayed.

Hi,

I believe that the best approach is the creation of a new SSL cert for this case since SSL certs must match the DNS entry. You may use even an auto signed certificate for this.

Lucas Lima

Atlassian Support

This widget could not be displayed.

Hi,

Well If you read my question, a new certificate is not an option, and SSL must not match the DNS entry, this is only a security setting to prevent false certicates.

In a controlled environment you kan easily in JAVA disable the hostname validation. All I'm asking is a setting, so I can decide whether or not, host name validation should be enabled.

And I think Stash might have a bug, since 5 out of 6 steps was working when enabling LDAPS, only user authencation failed.

This widget could not be displayed.

Did the screendump not go through?

This widget could not be displayed.

Obviously not in the Answer section. However in the Jira issue the screendump is attaached.

Suggest an answer

Log in or Sign up to answer
Community showcase
Posted Thursday in United States

Local Atlassian Research Workshop opportunity on Sep. 28th

We're looking for participants for another workshop at Atlassian! We need Jira admins who have interesting custom workflows, issue views, or boards. Think you have a story to sh...

35 views 0 0
View post

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you