Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-22-2009, 02:29 PM
Intermediate Member
 
Posts: 21
Default disabling ssl?

Hey there, is there a way to disable SSL? I keep getting errors in the administration console when accessing MTA and other settings which I believe is because i dont have a certificate. I will not ever be getting a commercial certificate and the wiki didn't really explain how to get around this. Im not really interested in SSL as all users will communicate through a secure vpn anyways.

Any ideas?

Errors obtained:
----------------------------
(1) The server's name "10.1.1.10" does not match the certificate's name "lina.seravitae.com". Somebody may be trying to eavesdrop on you.
(2) The certificate for "lina.seravitae.com" is signed by the unknown Certificate Authority "lina.seravitae.com". It is not possible to verify that this is a valid certificate.

Server error encountered: Message: system failure: server lina.seravitae.com zimbraRemoteManagementPrivateKeyPath (/opt/zimbra/.ssh/zimbra_identity) does not exists Error code: service.FAILURE Method: GetServerNIfsRequest Details:soap:Receiver
Reply With Quote
  #2 (permalink)  
Old 02-22-2009, 11:08 PM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

You can't disable SSL, try recreating the certificates.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 02-23-2009, 01:52 AM
Intermediate Member
 
Posts: 21
Default

Hi bill, thanks for the response. I was/am following the guide and get up to this step with an interesting response:


zimbra@lina:~$ keytool -delete -alias jetty -keystore /opt/zimbra/mailboxd/etc/keystore -storepass zimbra
keytool error: java.io.IOException: Keystore was tampered with, or password was incorrect


not sure what to do here. seeing as i never had a certificate of any kind (new install) i attempted the "Single-Node Self-Signed Certificate" example in the wiki, which went smoothly and apparently generated a self-signed certificate. However i still get an invalid certificate error in firefox, and the original very long error still shows up in the admin console when i try to navigate anything important. also certificates as an option isnt shown there. (shouldnt it be?)

thanks so far.
Reply With Quote
  #4 (permalink)  
Old 02-23-2009, 02:02 AM
Moderator
 
Posts: 7,928
Default

Code:
su - zimbra
zmcontrol -v
__________________
Reply With Quote
  #5 (permalink)  
Old 02-23-2009, 02:10 AM
Intermediate Member
 
Posts: 21
Default

Release 5.0.11_GA_2695.UBUNTU8 UBUNTU8 FOSS edition
Reply With Quote
  #6 (permalink)  
Old 02-23-2009, 05:57 PM
Zimbra Employee
 
Posts: 604
Default

This guide is probably more appropriate. http://wiki.zimbra.com/index.php?tit...ed_Certificate
__________________
Bugzilla - Wiki - Downloads - Before posting... Search!
Reply With Quote
  #7 (permalink)  
Old 02-23-2009, 09:26 PM
Intermediate Member
 
Posts: 21
Default

yes, that is the one i was referring to that i followed.

evidence:
------------------------------
root@lina:/opt/zimbra/bin# ./zmcertmgr viewdeployedcrt
::service mta::
notBefore=Feb 23 09:40:02 2009 GMT
notAfter=Feb 23 09:40:02 2010 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=lina.seravitae.com
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=lina.seravitae.com
SubjectAltName=
::service proxy::
notBefore=Feb 23 09:40:02 2009 GMT
notAfter=Feb 23 09:40:02 2010 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=lina.seravitae.com
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=lina.seravitae.com
SubjectAltName=
::service mailboxd::
notBefore=Feb 23 09:40:02 2009 GMT
notAfter=Feb 23 09:40:02 2010 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=lina.seravitae.com
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=lina.seravitae.com
SubjectAltName=
::service ldap::
notBefore=Feb 23 09:40:02 2009 GMT
notAfter=Feb 23 09:40:02 2010 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=lina.seravitae.com
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=lina.seravitae.com
SubjectAltName=
--------------------------------------


unfortunately still getting the same error

i should say at this point also, if it helps, that the self-signed certificate is used because i am doing a small intranet zimbra platform, using split-horizon dns.

Last edited by seravitae; 02-24-2009 at 03:47 AM..
Reply With Quote
  #8 (permalink)  
Old 02-27-2009, 06:04 AM
Intermediate Member
 
Posts: 21
Default

sorry to bump the thread but i have not discovered anything further about this problem. the self-signed cert is apparently installed, im not sure what else to try.

if anyone can shed any light i'd appreciate it! i think the slightly misleading title may cause people to not read the thread. is it worth me waiting and posting a fresh thread, or somehow editing the name of this one?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.