Hi all,

I've posted this in an existing thread, but didn't see the messages show up, so I thought I'd report here (apologies in advance - I know it's probably not considered the "thing to do").

First, the build info:

Code:
[zimbra@rose andy]$ zmcontrol -v


Release 6.0.3_GA_1915.F11_20091118105056 F11 FOSS edition.

[zimbra@rose andy]$
Now, zmcontrol start yields:

Code:
[zimbra@rose andy]$ zmcontrol start
Host xxx.xxx.xxx.xxx
Unable to determine enabled services from ldap.
Unable to determine enabled services. Cache is out of date or doesn't exist.
[zimbra@rose andy]$
Now, I've eventually tracked this down to a problem with the certificates having expired yesterday. SO I tried regenerating these using the recommended procedure with the following result (errors highlighted in red):

Code:
[root@rose bin]# ./zmcertmgr createca -new
** Creating /opt/zimbra/ssl/zimbra/ca/zmssl.cnf...done
** Creating CA private key /opt/zimbra/ssl/zimbra/ca/ca.key...done.
** Creating CA cert /opt/zimbra/ssl/zimbra/ca/ca.pem...done.
[root@rose bin]# ./zmcertmgr createcrt -new -days 365
Validation days: 365
** Creating /opt/zimbra/conf/zmssl.cnf...done
** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20101220141501
** Generating a server csr for download self -new -keysize 1024
** Creating /opt/zimbra/conf/zmssl.cnf...done
** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20101220141501
** Creating server cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.
** Saving server config key zimbraSSLPrivateKey...failed.
** Signing cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.
[root@rose bin]# ./zmcertmgr deploycrt self
** Saving server config key zimbraSSLCertificate...failed.
** Saving server config key zimbraSSLPrivateKey...failed.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to /opt/zimbra/conf/ca...done.
[root@rose bin]# ./zmcertmgr deployca self
** Importing CA /opt/zimbra/ssl/zimbra/ca/ca.pem into CACERTS...done.
** Saving global config key zimbraCertAuthorityCertSelfSigned...failed.
** Saving global config key zimbraCertAuthorityKeySelfSigned...failed.
** Copying CA to /opt/zimbra/conf/ca...done.
I'm hoping someone can point me in the right direction to get the certificates regenerated, as my users are beating down my door...

Thanks in advance!

Andy