Results 1 to 4 of 4

Thread: Zimbra 7.1.1 Starting nginx...nginx: [emerg] SSL_CTX_use_certificate_chain_file

  1. #1
    Join Date
    Dec 2009
    Posts
    75
    Rep Power
    6

    Default Zimbra 7.1.1 Starting nginx...nginx: [emerg] SSL_CTX_use_certificate_chain_file

    Hi

    I have an Problem on my 7.1.1 Master/Replica installation. When I restart the zimbra "zmcontrol stop" "zmcontrol start" nginx does not start anymore.

    Starting nginx...nginx: [emerg] SSL_CTX_use_certificate_chain_file("/opt/zimbra/conf/domaincerts/mydomain.com.crt") failed (SSL: error:02001002:system library:fopen:No such file or directory error:20074002:BIO routines:FILE_CTRL:system lib error:140DC002:SSL routines:SSL_CTX_use_certificate_chain_file:system lib)
    failed.

    This happens after the first domain where added.
    There is no "/opt/zimbra/conf/domaincerts/" folder on my system.
    We have no idea why this happens, we don't use an domain certificate (for this installation we don't want any).

    Have someone an idea how to fix this?

    yogg
    Release 7.1.2_GA_3268.UBUNTU8_64 UBUNTU8_64 NETWORK edition.

  2. #2
    Join Date
    Dec 2009
    Posts
    75
    Rep Power
    6

    Default

    No one with the same problem?
    Release 7.1.2_GA_3268.UBUNTU8_64 UBUNTU8_64 NETWORK edition.

  3. #3
    Join Date
    Jul 2011
    Posts
    7
    Rep Power
    4

    Default

    Hi,
    Same prob no result But in my case, i installed a second webstore (multiserver installation) and after finished installation, my IMAPPROXY hung up! When i will start the proxy-service i get the error:


    Starting nginx...nginx: [emerg] SSL_CTX_use_certificate_chain_file("/opt/zimbra/conf/domaincerts/<domainname>.crt") failed (SSL: error:02001002:system library:fopen:No such file or directory error:20074002:BIO routines:FILE_CTRL:system lib error:140DC002:SSL routines:SSL_CTX_use_certificate_chain_file:system lib)
    failed.

    So i didn't really know why he want to have a locale cert for the second webstore-server?

    Kind regards

  4. #4
    Join Date
    Jul 2011
    Posts
    7
    Rep Power
    4

    Default

    HI,

    found the problem! In my environment we us a loadbalancer who will check ther certs aso ... and on my second mailboxstore-server is sayed: zimbraReverseProxyMailMode Both

    That means:
    LDAP-Conf for WEbstore1: http
    LDAP-Conf for Webstore2: Both
    LDap-Conf for imapproxy: http

    So i think that the imapproxy would like to have a cert for the webstore2 if you just want to use HTTPS! But the webstore has none and the proxy will check it on his own side and can't find one!

    SO be sure to use the same config and the second side and the "zimbraReverseProxyMailMode"!

    You can check it with:
    " zmprov -l gs `zmhostname` |grep zimbraReverseProxyMailMode"

    Hope this will help u

    Kind regards

Similar Threads

  1. admin consol blank after 5.0.3 upgarde
    By maumar in forum Administrators
    Replies: 6
    Last Post: 03-21-2008, 06:16 AM
  2. Replies: 12
    Last Post: 02-25-2008, 07:28 PM
  3. Cleanup after many upgrades
    By tobru in forum Installation
    Replies: 1
    Last Post: 12-23-2007, 09:21 AM
  4. dspam logrotate errors
    By michaeln in forum Users
    Replies: 7
    Last Post: 02-19-2007, 12:45 PM
  5. huge log size
    By rmvg in forum Administrators
    Replies: 5
    Last Post: 01-02-2007, 10:39 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •