Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-23-2008, 01:16 PM
Intermediate Member
 
Posts: 19
Default [SOLVED] Commercial Certificate issue - thawte - again

hi guys

i got Zcs network edition 5.06 and cannot get my thawte certificates to work.

i followed the instructions on [SOLVED] Commercial Certificate - Thawte - ZC5
and on the WIKI on installing commercial certificates and still got to nowhere ...

o downloaded the server roots and unziped the files in the web gui

have put the root.ca and the premiumserver as intermediate alwayes i got this weird message

Message: Your certificate was not installed due to the error : system failure: XXXXX ERROR: Invalid Certificate: Error code: ZaCertWizard.prototype.installCallback Method: AjxException.UNKNOWN_ERROR Details:system failure: XXXXX ERROR: Invalid Certificate:

the certificate is x509 apache certificate of THAWTE.

any help will be appreciated

shay
Reply With Quote
  #2 (permalink)  
Old 06-23-2008, 05:38 PM
Trained Alumni
 
Posts: 70
Default

I think you need to have the base64 encoded version for it to work. Your cert should look like
Code:
-----BEGIN CERTIFICATE-----
encoded stuff
-----END CERTIFICATE-----
If you have the plain-text portions, I think those need to be edited out. You also need to make sure that you have the base64 encoded versions of the root and intermediary certs too...those are the ones that end in .txt from Thawte's certificates.
Reply With Quote
  #3 (permalink)  
Old 06-24-2008, 03:02 PM
Intermediate Member
 
Posts: 19
Default this is the certificate type i have.

they are all encoded within the two lines.
what you did say about editing out?
i did all that is written in the wiki.
Reply With Quote
  #4 (permalink)  
Old 06-24-2008, 04:39 PM
Trained Alumni
 
Posts: 70
Default

I have seen x509 certs (not specifically from Thawte) that have all the plain text portions at the top, so you get a cert that starts with
Code:
Certificate
     Data:
       Version: 3 (0x2)
       Serial Number: 1 (0x1)
       Signature Algorithm: md5WithRSAEncryption
       Issuer: C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc,
               OU=Certification Services Division,
               CN=Thawte Server CA/emailAddress=server-certs@thawte.com
       blahblahblah
But, if all your certificate has is the encoded stuff, that wouldn't be the problem. I also don't know that cert in that format won't work...I just know that I used only the base64 encoded one, and that works

Do you have a single-server setup, or is it multiple server?
Reply With Quote
  #5 (permalink)  
Old 06-25-2008, 11:27 AM
Intermediate Member
 
Posts: 19
Default i have a single server setup

maybe its the type of the cert? apache was enough when i did that on the last scalix server i had.

i have all the files encoded in text edition. nowhere yo go from here.

is there another option ?

galezer
Reply With Quote
  #6 (permalink)  
Old 06-25-2008, 04:56 PM
Moderator
 
Posts: 6,237
Default

Quote:
Originally Posted by galezer View Post
i got Zcs network edition 5.06 and cannot get my thawte certificates to work.

Message: Your certificate was not installed due to the error : system failure: XXXXX ERROR: Invalid Certificate: Error code: ZaCertWizard.prototype.installCallback Method: AjxException.UNKNOWN_ERROR Details:system failure: XXXXX ERROR: Invalid Certificate:
That seems like the error described here: http://www.zimbra.com/forums/adminis...s-5-0-6-a.html

A) The easiest workaround is to specify "--- All Servers ---" as the target server when installing the commericial cert.

B) The other way is to create the commercial_ca.crt (concantenated chain file) manually under /opt/zimbra/ssl/zimbra/commercial.

Bug 28085 - zmcertmgr doesn't break down the concatenated commercial cert from Ldap
Reply With Quote
  #7 (permalink)  
Old 06-26-2008, 01:30 AM
Intermediate Member
 
Posts: 19
Default i tried with "all servers" - i get new error message

this message reads :
AjxException.UNKNOWN_ERROR Details:system failure: XXXXX ERROR: failed to create jetty.pkcs12

another bug perhaps ?

something else that can help me here?
Reply With Quote
  #8 (permalink)  
Old 06-26-2008, 02:07 AM
Intermediate Member
 
Posts: 19
Wink at last it did work! using " all servers"

i cut some white space after the --end-- flag and
thanks for all that helped - i mark this thread solved.

thank for all of you that helped - i like this forum.

galezer
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.