Results 1 to 2 of 2

Thread: [SOLVED] zmprov not working after unsuccessful cert installation

  1. #1
    Join Date
    Jan 2010
    Rep Power

    Default [SOLVED] zmprov not working after unsuccessful cert installation

    I was using a self cert and was trying to install a new certificate from CAroot. I was following the instruction in wiki and ain't sure which step I did wrong. So, I tried re-gen a self cert again and found saving SSL Key failed. In fact, I found zmprov fail to work altogether.

    [root@mailserv ~]# /opt/zimbra/bin/zmcertmgr createcrt self -new
    ** Creating /opt/zimbra/conf/zmssl.cnf...done
    ** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20100107170839
    ** Retrieving server config key zimbraSSLCertificate...failed.
    ** Retrieving server config key zimbraSSLPrivateKey...failed.
    ** Generating a server csr for download self -keysize 1024
    ** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20100107170845
    ** Creating server cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.
    ** Saving server config key zimbraSSLPrivateKey...failed.
    ** Signing cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.

    [zimbra@mailserv ~]$ zmprov -l gcf zimbraCertAuthorityKeySelfSigned
    ERROR: service.FAILURE (system failure: ZimbraLdapContext) (cause: PKIX path validation failed: signature check failed)

    Now, I think I am in deep trouble. The zimbra server is still running fine but I am so afraid if I have to reboot at some point and found everything is gone. Can someone please help to point out how to fix the zmprove failure?

    Thank you very much.

  2. #2
    Join Date
    Jan 2010
    Rep Power


    Well actually, as it turn out, I follow the instructions in
    Recreating a Self-Signed SSL Certificate - Zimbra :: Wiki
    correctly. But the only thing is, I found that after new certificate installation, zmprov will not work until zmcontrol stop and restart. However, since the instructions in wiki instruct to use zmprov to verify the cacert right after "zmcertmgr deploycrt". This scared the daylight out of me to find zmprov suddenly stop working.

Similar Threads

  1. Unable to script zmprov changes completely
    By todd_dsm in forum Installation
    Replies: 1
    Last Post: 12-16-2009, 06:39 AM
  2. Failed Commercial Cert Migration
    By solarsail in forum Administrators
    Replies: 10
    Last Post: 04-23-2009, 01:03 AM
  3. Replies: 4
    Last Post: 03-17-2008, 06:53 PM
  4. [SOLVED] 5.0GA: zmprov not working anymore
    By fisch09 in forum Installation
    Replies: 3
    Last Post: 01-05-2008, 07:21 PM
  5. Installation succeeds, but admin panel not working...
    By Svartalf in forum Installation
    Replies: 5
    Last Post: 02-07-2006, 04:57 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts