Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-37546

JIRA does not validate SSL certificates and requires restart on any certificate changes

    XMLWordPrintable

Details

    Description

      SSL support seems to be a big critical issues with JIRA that was ignored for quite some time.

      SSL certificates are usually replaced once a year (average), and considering the number of system that JIRA has to interact with the number of certificates could easily go above 15 / jira instance.

      Why? Just count few other instances to connect with: JIRA, Confluence, Bamboo, Crucible, SMTP servers, IMAP servers, ....

      Now JIRA fails to validate even certificates that are recognized perfectly by all 5 major browsers, requiring admins to manually add the certificates to the truststore and to restart JIRA.

      So, if you have a JIRA instance with ~15 certificates you would be required to restart JIRA ~15 times an year (every ~20 days) just to repair broken communication with other systems.

      This is something unacceptable for a system that is supposed to be up 24x7.

      There are at least two things that have to be fixed here:

      • Accept any SSL certificates that are globally acceptable.
      • Provide a way to install new certificated that does not require instance restart.

      Ideally, SSL authentications from AppLinks windows, SMTP and IMAP/POP3 should prompt the user to accept a new certificates.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              73f0b2e75f82 Sorin Sbarnea (Citrix)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: