Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-06-2008, 06:53 AM
Special Member
 
Posts: 117
Default [SOLVED] GoDaddy certs on 5.0.6

I went through the process using the wizard, but I an getting an error.

I did go through the process of generating the CSR, submitting that to GoDaddy. I got back my certificate and the intermediate cretificate.

I downloaded their root certificate and use those three in the wizard.

Any ideas?
Attached Images
File Type: jpg zimbra cert error.JPG (30.7 KB, 436 views)
Reply With Quote
  #2 (permalink)  
Old 06-09-2008, 02:15 AM
Senior Member
 
Posts: 54
Default

I got EXACTLY the same message on a new install of 5.06 NE on RHEL 5.1 64.
Reply With Quote
  #3 (permalink)  
Old 06-09-2008, 09:57 AM
Senior Member
 
Posts: 54
Default GoDaddy certs on 5.0.6

Hi All,

I've followed the instructions in the wiki for 5.x godaddy certificate install but it keeps defaulting back to the self-signed certificate. First I tried to install everything with the web gui, which gave an error that many others have seen around here. Then I manually put the files from godaddy along with their root certificate in the /opt/zimbra/ssl/zimbra/commercial folder then I restarted services but I'm still getting the signed certificate and no certificate installed in the admin gui either.

Anybody have any advice?

I'm on RHEL 5.1 64 using NE.


Thanks,

Tony
Reply With Quote
  #4 (permalink)  
Old 06-09-2008, 10:41 AM
Special Member
 
Posts: 117
Default

Just out of curiosity. When you submitted the request to godaddy whih server did you specify? Tomcat or Apache?

Also, how many files did you get back from GD? I think I got back 4.

Bundle, mine, intermediate and cross intermediate.

I assume that one specified the bundle as their root, and add a second intermediate to the list to include the cross intermediate?
Reply With Quote
  #5 (permalink)  
Old 06-09-2008, 10:45 AM
Senior Member
 
Posts: 54
Default

I did Apache, since Tomcat doesn't exist in 5.x.

I got back 2 files, then I had to download the root certificate manually.
My domain cert and an intermediate cert.
Reply With Quote
  #6 (permalink)  
Old 06-09-2008, 11:48 PM
Zimbra Employee
 
Posts: 55
Default

Please check the following:

(1) current aliases in the keystore
keytool -list -keystore /opt/zimbra/mailboxd/etc/keystore -storepass `zmlocalconfig -s -m nokey mailboxd_keystore_password`

(2) delete all aliases except the jetty alias following this example
keytool -delete -alias tomcat -keystore /opt/zimbra/mailboxd/etc/keystore -storepass `zmlocalconfig -s -m nokey mailboxd_keystore_password`
(3) verify the cert and the private key match
/opt/zimbra/bin/zmcertmgr verifycrt comm /path/to/private_key /path/to/server_crt
(4) verify the private_key , server_cert, and the chain
/opt/zimbra/bin/zmcertmgr verifycrt /path/to/private_key /path/to/server_cert /path/to/chain_cert
(4) deploy
/opt/zimbra/bin/zmcertmgr deploycrt comm /path/to/private_key /path/to/server_cert /path/to/chain_cert
(5) restart the zimbra services
Reply With Quote
  #7 (permalink)  
Old 06-10-2008, 02:31 AM
Senior Member
 
Posts: 54
Default

Thanks for your help.

(1) Only listed the Jetty alias
(2) None to delete
(3) Got the error that commercial_ca.crt doesn't exist. I renamed commercial.crt to commercial_ca.crt and now the verify works
(4) I had to change this command to verifycrtchain for it to work properly, but it informs me:

error 26 at 0 depth lookup:unsupported certificate purpose

And that's where I am. When I got the cert from GoDaddy I chose Apache as my server. The only other choice in the list I saw that I thought was relevant was Red Hat. Should I re-issue the crt and choose a different server type than apache?

Thanks Again
Reply With Quote
  #8 (permalink)  
Old 06-10-2008, 06:57 AM
Zimlet Guru & Moderator
 
Posts: 467
Default

I think you might want to see if you can get it re-issued as Tomcat. I use Godaddy, exported it as a Tomcat key, andhad no problems with it.
Reply With Quote
  #9 (permalink)  
Old 06-10-2008, 06:58 AM
Zimlet Guru & Moderator
 
Posts: 467
Default

Try not using their root certificate. See if it's conflicting against a certificate already installed.
Reply With Quote
  #10 (permalink)  
Old 06-10-2008, 07:30 AM
Special Member
 
Posts: 117
Default

It won't let you proceed without the root certificate
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.