Page 2 of 2 FirstFirst 12
Results 11 to 15 of 15

Thread: [SOLVED] Zimbra Certificates have expired and I'm having difficulty regenerating them

  1. #11
    Join Date
    Aug 2008
    Posts
    7
    Rep Power
    7

    Default Thanks

    Thank you very much. Your very clear instructions helped me to resolve my problem.

  2. #12
    Join Date
    Jun 2011
    Posts
    5
    Rep Power
    4

    Default adavison17 Thanks A lot

    My issue is resolved.........................

  3. #13
    Join Date
    Oct 2009
    Posts
    1
    Rep Power
    6

    Default

    Quote Originally Posted by adavison17 View Post
    Thanks Bill,

    The third codebox had the results of this procedure, but I've executed it again just in case I missed something. Results below:
    Code:
    
    [root@rose bin]# ./zmcertmgr createca -new
    ** Creating /opt/zimbra/ssl/zimbra/ca/zmssl.cnf...done
    ** Creating CA private key /opt/zimbra/ssl/zimbra/ca/ca.key...done.
    ** Creating CA cert /opt/zimbra/ssl/zimbra/ca/ca.pem...done.
    [root@rose bin]# ./zmcertmgr  createcrt -new -days 365
    Validation days: 365
    ** Creating /opt/zimbra/conf/zmssl.cnf...done
    ** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20101220203916
    ** Generating a server csr for download self -new -keysize 1024
    ** Creating /opt/zimbra/conf/zmssl.cnf...done
    ** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20101220203916
    ** Creating server cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.
    ** Saving server config key zimbraSSLPrivateKey...failed.
    ** Signing cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.
    [root@rose bin]# ./zmcertmgr deploycrt self
    ** Saving server config key zimbraSSLCertificate...failed.
    ** Saving server config key zimbraSSLPrivateKey...failed.
    ** Installing mta certificate and key...done.
    ** Installing slapd certificate and key...done.
    ** Installing proxy certificate and key...done.
    ** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
    ** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
    ** Installing CA to /opt/zimbra/conf/ca...done.
    [root@rose bin]# ./zmcertmgr deployca
    ** Importing CA /opt/zimbra/ssl/zimbra/ca/ca.pem into CACERTS...done.
    ** Saving global config key zimbraCertAuthorityCertSelfSigned...failed.
    ** Saving global config key zimbraCertAuthorityKeySelfSigned...failed.
    ** Copying CA to /opt/zimbra/conf/ca...done.
    [root@rose bin]# ./zmcertmgr viewdeployedcrt
    ::service mta::
    notBefore=Dec 20 09:39:22 2010 GMT
    notAfter=Dec 20 09:39:22 2011 GMT
    subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=host.domain.com
    issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=host.domain.com
    SubjectAltName=
    ::service proxy::
    notBefore=Dec 20 09:39:22 2010 GMT
    notAfter=Dec 20 09:39:22 2011 GMT
    subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=host.domain.com
    issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=host.domain.com
    SubjectAltName=
    ::service mailboxd::
    notBefore=Dec 20 09:39:22 2010 GMT
    notAfter=Dec 20 09:39:22 2011 GMT
    subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=host.domain.com
    issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=host.domain.com
    SubjectAltName=
    ::service ldap::
    notBefore=Dec 20 09:39:22 2010 GMT
    notAfter=Dec 20 09:39:22 2011 GMT
    subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=host.domain.com
    issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=host.domain.com
    SubjectAltName=
    [root@rose bin]#
    Thanks Bill!

    Andy
    I had the same issue: resolved it using
    Code:
    zmlocalconfig -e ssl_allow_untrusted_certs=true

  4. #14
    Join Date
    Apr 2013
    Posts
    1
    Rep Power
    2

    Default Thanks

    Quote Originally Posted by Berry View Post
    I had the same issue: resolved it using
    Code:
    zmlocalconfig -e ssl_allow_untrusted_certs=true
    Thanks to All!

    Specially Berry... Cheers

  5. #15
    Join Date
    Apr 2013
    Posts
    8
    Rep Power
    2

    Default

    I have following all off the instruction.
    But i still go error when i try to replace the certificate.
    [root@mail ~]# /opt/zimbra/bin/zmcertmgr createca -new
    /opt/zimbra/bin/zmcertmgr: line 96: /C=US/ST=N\/A/L=N\/A/O=Zimbra Collaboration Suite/OU=Zimbra
    Collaboration Suite/CN=${mail.gs-golf.com}: bad substitution
    ** Creating /opt/zimbra/ssl/zimbra/ca/zmssl.cnf...done
    ** Creating CA private key /opt/zimbra/ssl/zimbra/ca/ca.key...failed.

    Generating a 1024 bit RSA private key
    .++++++
    ...............................++++++
    writing new private key to '/opt/zimbra/ssl/zimbra/ca/ca.key'
    -----
    Subject does not start with '/'.
    problems making Certificate Request

    ** Creating CA cert /opt/zimbra/ssl/zimbra/ca/ca.pem...failed.

    /opt/zimbra/ssl/zimbra/ca/ca.csr: No such file or directory

    [root@mail ~]#
    Anybody have this problem before.

Similar Threads

  1. [SOLVED] Zimbra SSL Certificates Expired
    By madods in forum Administrators
    Replies: 4
    Last Post: 10-04-2010, 03:44 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •