Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-05-2009, 10:51 AM
Intermediate Member
 
Posts: 20
Default Multiple Commercial SSL Certs

Hi,

Is it possible to install more than one SSL certificate on a Zimbra server? I mean I want both new-imap.mydomain.com and old-imap.mydomain.com (BOTH pointing to the same ip) being used. I own the certificates for these two subdomains. One certificate is installed correctly (new-imap.mydomain.com) but it complains when installing the second one using the certificate wizard

Message: invalid request: Server with id old-imap.mydomain.com could not be found Error code: service.INVALID_REQUEST Method: GetCSRRequest Details:soap:Sender

TIA

edit: Wildcard Cert is not a solution!

Last edited by nrgyz; 01-05-2009 at 10:56 AM..
Reply With Quote
  #2 (permalink)  
Old 01-05-2009, 11:09 AM
Moderator
 
Posts: 6,237
Default

At the moment no, you can't use multiple certs for ldap/mailboxd/mta/proxy: Bug 8128 - multiple SSL certificates on one server
Some people use this method if they need to keep existing certs intact: Multiple SSL Virtual Hosts - Zimbra :: Wiki

Quote:
Originally Posted by nrgyz View Post
edit: Wildcard Cert is not a solution!
Totally understandable, however what your describing could be solved with a subjectAltName, if your ok with generating a new certificate that is. The -subjectAltNames argument allows you to specify additional hosts that may use the certificate other than the one listed in the subject: Administration Console and CLI Certificate Tools - Zimbra :: Wiki

Fixed in 5.0.10: Bug 30598 - subjectAltName doesn't work correctly using zmcertmgr

(Might also set the old-imap.mydomain.com under admin console > domain > virtual host tab.)

Last edited by mmorse; 01-05-2009 at 11:18 AM.. Reason: virtual host may be handy for things later
Reply With Quote
  #3 (permalink)  
Old 01-05-2009, 12:24 PM
Intermediate Member
 
Posts: 20
Default

Hi mmorse,

I'll take a look at those suggestions you gave me. I need to make sure that my certificate authority (GoDaddy) will accept a subjectAltName.

Thanks for your quick reply!
Reply With Quote
  #4 (permalink)  
Old 02-25-2009, 07:46 AM
Loyal Member
 
Posts: 78
Default

Hello,

It would have been possible to tweak perdition's config file to point to dedicated certificates for pop3s and imaps, but how about nginx one ?

Regards,

Artturi
__________________
Artturi
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.