I'm having a problem with security certificates following an upgrade to 4.0.

zmprov no longer works, it would seem to be something to do with a trust issue.

Code:
[zimbra@zs1 ~]$ zmprov 
[] ERROR: java.security.cert.CertificateExpiredException: NotAfter: Sun Jul 09 14:50:44 BST 2006
ERROR: zclient.IO_ERROR (invoke java.security.cert.CertificateException: Untrusted Server Certificate Chain, server: localhost) (cause: javax.net.ssl.SSLHandshakeException java.security.cert.CertificateException: Untrusted Server Certificate Chain)
I attempted to recreate the certificate with little luck.

Code:
[root@zs1 zimbra]# zmcreatecert 
** Importing CA

keytool error: java.lang.Exception: Certificate not imported, alias <my_ca> already exists
** Creating keystore

** Creating server cert request

Generating a 1024 bit RSA private key
........++++++
...........++++++
writing new private key to '/opt/zimbra/ssl/ssl/server/server.key'
-----
** Signing cert request

Using configuration from /opt/zimbra/ssl/ssl/zmssl.cnf
Check that the request matches the signature
Signature ok
Certificate Details:
        Serial Number: 7 (0x7)
        Validity
            Not Before: Aug 21 10:43:39 2006 GMT
            Not After : Aug 21 10:43:39 2007 GMT
        Subject:
            countryName               = US
            stateOrProvinceName       = N/A
            organizationName          = Zimbra Collaboration Suite
            commonName                = zs1.cromwells.co.uk
        X509v3 extensions:
            X509v3 Basic Constraints: 
                CA:FALSE
            Netscape Comment: 
                OpenSSL Generated Certificate
            X509v3 Subject Key Identifier: 
                00:6C:C7:C4:3F:84:DD:38:E1:EE:75:FC:20:88:37:51:AE:48:8C:8F
            X509v3 Authority Key Identifier: 
                DirName:/C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite
                serial:A5:C8:2E:FF:BD:0D:9B:23

            X509v3 Key Usage: 
                Digital Signature, Non Repudiation, Key Encipherment
Certificate is to be certified until Aug 21 10:43:39 2007 GMT (365 days)

Write out database with 1 new entries
Data Base Updated
Signature ok
subject=/C=US/ST=NA/L=NA/O=Zimbra/OU=Zimbra/CN=zs1.cromwells.co.uk
Getting CA Private Key
[root@zs1 zimbra]# zmcertinstall 
** Importing server cert

/opt/zimbra/bin/zmcertinstall: line 81: [: =: unary operator expected
cp: missing destination file operand after `/opt/zimbra/conf/smtpd.key'
Try `cp --help' for more information.
[root@zs1 zimbra]# zmcertinstall mailbox
** Importing server cert

keytool error: java.lang.Exception: Failed to establish chain from reply
[root@zs1 zimbra]#
Any pointers?