Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-10-2009, 01:44 PM
Junior Member
 
Posts: 8
Question Outlook users getting certificate warning

All of my outlook users are getting a server certificate warning.
We have a mix of outlook clients that include outlook 2002, 2003, and 2007.
We are not using the outlook connector but are accessing the Zimbra mail server via pop3 with ssl for incoming on port 995. When the users open outlook they are getting this warning

"The server you are connecting to is using a security certificate that could not be verified. A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider. Do you wish to continue using this server? Yes No"

I have added the server to the trusted sites in the Internet Options (Intranet) but did not solve. I have been reading a lot of stuff from the web but it all has to do with Exchange and Outlook. The certificate has not expired and was created from the SUSE/Zimbra mail server in our local domain. Can someone please help me figure out how to stop this pop up. It is not causing any problems with users receiving their mail as long as they click yes. It is just an annoyance.

This was not a problem for our Thunderbird users, we just select accept always and it went away. I wish all my users would use Thunderbird.
Reply With Quote
  #2 (permalink)  
Old 02-10-2009, 01:56 PM
y@w y@w is offline
Moderator
 
Posts: 658
Default

Outlook is displaying that because your certificate is probably self-signed. You can either install a commercial certificate or here's an example of how to force Windows to accept the certificate: Microsoft Supportability e-Newsletter : Self-Signed Certificate issue when connecting to the exchange server
__________________
What a n00b!
Reply With Quote
  #3 (permalink)  
Old 02-12-2009, 04:13 PM
Junior Member
 
Posts: 8
Default outlook clients and ssl certificate

The MS site that you point to may work if you are running Vista and using outlook for web clients. We are using XP pro and regular outlook clients and do not have the option to download and automatically install the self signed certificate. My question still stands how do I get this done.

What ca file do I need to bring from the Zimbra server to the XP client or cell phone and how to I install it?
Reply With Quote
  #4 (permalink)  
Old 05-04-2009, 07:40 AM
Intermediate Member
 
Posts: 16
Default

I have the same issue, was the fix ever found?
Reply With Quote
  #5 (permalink)  
Old 05-04-2009, 08:02 AM
Junior Member
 
Posts: 8
Angry "Outlook users getting certificate warning"

The only solution that we have found is to purchase a certificate from a known authority. Outlook will not accept self signed certificates. Neither will Smart phones/Blackberry's.

If you find a way around this please let me know.

GaryC
Reply With Quote
  #6 (permalink)  
Old 06-25-2009, 06:59 AM
New Member
 
Posts: 4
Default

I know this is too late to help any of the old posters, but it may help other with the same question...

Assuming the Zimbra devs don't move the file, the command:

openssl x509 -in /opt/zimbra/ssl/zimbra/ca/ca.pem -outform DER -out ca.der

will generate the CA root certificate you need in order for Windows to import it properly. You can then copy the resulting ca.der file to your Windows box and double-click it (or import it using the wizard.) It will install into the "Trusted Root Certification Authorities" section of your certificates window. Outlook and HTTPS webmail will no longer generate those annoying errors.

Please keep in mind that if the Zimbra CA is pre-generated and not generated at the time of installation, this will open you up to misidentified sites that sign their own certs with the same CA. I don't know if this is the case or not, but would recommend building your own CA if you're unsure.

[SOLVED] Rolling Your Own CA and Installing Certificates in Zimbra

will get that done for you. And you won't have to guess at which ca.pem file to use.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.