Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-01-2008, 10:22 PM
Senior Member
 
Posts: 65
Default [SOLVED] 5.0.7 Upgrade Failure - when hostname of server does not match cert

I attempted to upgrade ZCS 5.0.6NE to 5.0.7 tonight and everything was gonig normal like all the other installs but then I started getting a massive amount of these errors.


ERROR: service.FAILURE (system failure: ZimbraLdapContext) (cause: javax.net.ssl.SSLPeerUnverifiedException hostname of the server 'notthereal.servername' does not match the hostname in the server's certificate.)

It tried to continue and finish the install.

When I tired starting the server up, I got this error

Unable to determine enabled services from ldap.
Enabled services read from cache. Service list may be inaccurate.
Unable to determine enabled services from ldap.

and then everything started up but I cannot connect.

I have called support and also submitted a case via email.

Reply With Quote
  #2 (permalink)  
Old 07-02-2008, 12:19 AM
Moderator
 
Posts: 6,236
Default

Handled by support - he'll update the thread later with details after some sleep.
Reply With Quote
  #3 (permalink)  
Old 07-02-2008, 07:38 AM
Senior Member
 
Posts: 65
Default

Thanks very much to mmorse and network support person Jason Bryan I'm back up and running with 5.0.7. Jason filed a very detailed bug description and I think that best explains everything. Thanks!

Bug 29600


Hurstel
Reply With Quote
  #4 (permalink)  
Old 07-02-2008, 03:11 PM
Active Member
 
Posts: 36
Default

Would we be safe from this bug if the host name does not match, but the web access url is listed as an alt name in the cert?
Reply With Quote
  #5 (permalink)  
Old 07-02-2008, 04:42 PM
Intermediate Member
 
Posts: 23
Default

About the possible fix in the bug report...

I have a name mismatch cert on my test server, and the install didn't complete for me until I ran zmlocalconfig -e zimbra_require_interprocess_security=0.

That is, it appears to me that zmlocalconfig -e ssl_allow_untrusted_certs=TRUE does not allow for name mismatches. (I tried that first, without success).

--Chris
Reply With Quote
  #6 (permalink)  
Old 07-02-2008, 05:15 PM
Moderator
 
Posts: 1,531
Default

will this fail on a wildcart cert? (*.domain.com)
Reply With Quote
  #7 (permalink)  
Old 07-02-2008, 05:41 PM
Zimbra Employee
 
Posts: 112
Smile Upgrade Failure answers!

janderson,

This would work fine as long as the server hostname (not necessarily the name you access the server from via http, imap, pop, etc) is either listed as the primary hostname or the SubjectAltName of the certificate.

cjstone,

You're correct. ssl_allow_untrusted_certs=TRUE is NOT a good workaround. We're working on correcting some code to allow that setting to work in 5.0.8.

bdial,

Wildcard certificates will work correctly.
Reply With Quote
  #8 (permalink)  
Old 07-02-2008, 06:56 PM
Senior Member
 
Posts: 61
Default

Should you maybe point to this thread from the following announcement thread?
5.0.7 NE Released!

I've scheduled downtime on Friday to upgrade from 4.5.9, is there any chance (a safe) 5.0.8 will be out by then? There look to be some useful calendar fixes in 5.0.7.
Reply With Quote
  #9 (permalink)  
Old 07-03-2008, 06:11 AM
Active Member
 
Posts: 36
Default

tonster, thanks for clearing that up!
Reply With Quote
  #10 (permalink)  
Old 07-04-2008, 02:03 AM
Project Contributor
 
Posts: 116
Default

Same problem here when upgrading from 5.0.5 to 5.0.7.
Fortunately, I've not found problems to revert to 5.0.5 but I prefer to wait until 5.0.8 arrives instead of try to ugrade again applying workarounds.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.