CCMA Errors with Not Authorized URL's
プラットフォームについて: Server および Data Center のみ。この記事は、Server および Data Center プラットフォームのアトラシアン製品にのみ適用されます。
Support for Server* products ended on February 15th 2024. If you are running a Server product, you can visit the Atlassian Server end of support announcement to review your migration options.
*Fisheye および Crucible は除く
要約
This article covers communication issues between the Confluence Cloud Migration Assistant (CCMA) and Atlassian Cloud infrastructure.
環境
This problem impacts Confluence Server and Data Center.
診断
When using CCMA for migration, you might encounter error messages in the migration logs related to TLS communication with Atlassian Cloud infrastructure. These error messages might include:
com.atlassian.migration.agent.okhttp.IOHttpException: An IO exception occurred when communicating with a downstream service
Caused by: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
原因
The issue arises when the certificates on the Java TrustStore that Confluence uses are out-of-date and don't match the current certificates on Atlassian Cloud infrastructure.
ソリューション
Before modifying the Java TrustStore, ensure you have a backup. If possible, test any commands on a staging server first.
To fix the issue, you need to manually import the current certificates used by Atlassian Cloud infrastructure into Confluence's Java TrustStore. Here's how to do it:
First, identify the URLs that CCMA needs to communicate with. You can find the current URLs in the CCMA communications section of IP addresses and domains for Atlassian cloud products documentation page. Create a dedicated public certificate file for each URL using the following commands:
keytool -printcert -sslserver [URL] -rfc > [filename].crt
Next, import the saved public certificates into Confluence's Java TrustStore using the following commands:
keytool -import -keystore [absolute_path_to_truststore] -storepass <password> -alias [alias] -file [filename].crt
- Finally, restart Confluence and rerun the CCMA.
By following these steps, you should be able to resolve the communication failure between CCMA and Confluence Cloud infrastructure.