A re-keyed SSL Certificate installs correctly (the following is a reinstall just to verify that it's working. that's why the cp warning shows up):
Next, I restart the services with zmcontrol restart, and zmmailboxdctl restart,
# /opt/zimbra/bin/zmcertmgr deploycrt comm commercial.crt commercial_ca.crt
** Verifying commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: commercial.crt: OK
** Copying commercial.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
cp: `commercial.crt' and `/opt/zimbra/ssl/zimbra/commercial/commercial.crt' are the same file
** Appending ca chain commercial_ca.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
cp: `commercial_ca.crt' and `/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' are the same file
** Importing certificate /opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt to CACERTS as zcs-user-commercial_ca...done.
** NOTE: mailboxd must be restarted in order to use the imported certificate.
** Saving server config key zimbraSSLCertificate...done.
** Saving server config key zimbraSSLPrivateKey...done.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to /opt/zimbra/conf/ca...done.
When I viewinstalledcerts, I get the correct certificates and issue and expiration dates. When I view the web GUI certificates page, I see the correct certificate information with the valid issue, and expiration dates. However, when I go to my webmail using google chrome, I see the OLD certificate information. Firefox doesn't even let me in any more and gives (Error code: sec_error_revoked_certificate). I have cleared my cache, and all sessions.
Everything looks like it installed properly but it does not get applied. I am using zimbra 8.0.6 with the heartbleed fix applied using a godaddy wildcard cert.