Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-20-2009, 12:34 PM
Active Member
 
Posts: 28
Default TLS Errors after installing Thawte cert

I am attempting a new install of zimbra. I am new to the product.
I was using a self generated cert until ready to go live, when I installed a cert from thawte.

Prior to the install, the self-signed cert smtp worked fine, but couldn't get IE to trust the cert- thus purchasing one from thawte.

Since installation, the browsers don't complain about the ssl, but email clients can't access smtp.

Could postfix still be looking at the old cert somehow and puking on that? If so, how do I verify?

Thank you for your patience.
Reply With Quote
  #2 (permalink)  
Old 03-25-2009, 12:56 PM
Active Member
 
Posts: 28
Default Still stuck

I'm still stuck....I'm *not* trying to be smart here- does this mean that I'm the only person in the history of zimbra that has had trouble installing a third party cert?

Reply With Quote
  #3 (permalink)  
Old 03-25-2009, 01:49 PM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Have you searched the forums or tried these instructions?
__________________
Regards


Bill
Reply With Quote
  #4 (permalink)  
Old 03-26-2009, 08:34 AM
Active Member
 
Posts: 28
Default Doesn't match the wizard

well...I *thought* I did.

I have since generated a new csr via the web ui and gotten thawte to generate a new cert.
I copied the cert to notepad and saved as mycert.pem
I go through the install cert wizard and it asks for a Certificate as well as a CA. It won't let me give it same file for both.

So...where do I go from there?
Reply With Quote
  #5 (permalink)  
Old 03-26-2009, 09:12 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

[SOLVED] Commercial cert Thawte
__________________
Regards


Bill
Reply With Quote
  #6 (permalink)  
Old 03-26-2009, 09:15 AM
Active Member
 
Posts: 28
Default Progress!?

OK...I got past the UI deal by the second post in this thread.
[SOLVED] Commercial Certificate - Thawte - ZC5

Whoo Hoo!!

-----
Now, slapd won't start.


$ zmcontrol start
Host <machine name>
Starting ldap...Done.
FAILED
Failed to start slapd. Attempting debug start to determine error.
TLS: error:0906D06C EM routines EM_read_bio:no start line pem_lib.c:647
TLS: error:0906D06C EM routines EM_read_bio:no start line pem_lib.c:647
TLS: error:02001002 ystem library:fopen:No such file or directory bss_file.c:356
TLS: error:20074002:BIO routines:FILE_CTRL ystem lib bss_file.c:358
main: TLS init def ctx failed: -1
Reply With Quote
  #7 (permalink)  
Old 03-26-2009, 09:25 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Which version of openssl do you have installed?
__________________
Regards


Bill
Reply With Quote
  #8 (permalink)  
Old 03-26-2009, 09:28 AM
Active Member
 
Posts: 28
Default

openssl 0.9.8i


...and THANK YOU for the quick responses!!!!!

Last edited by rogle; 03-26-2009 at 09:29 AM.. Reason: thanks
Reply With Quote
  #9 (permalink)  
Old 03-26-2009, 09:32 AM
Active Member
 
Posts: 28
Default new error

sudo /opt/zimbra/bin/zmcertmgr deploycrt comm /tmp/commercial.crt /tmp/commercial_ca.crt
** Verifying /tmp/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: /tmp/commercial.crt: OK
** Copying /tmp/commercial.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Appending ca chain /tmp/commercial_ca.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Saving server config key zimbraSSLCertificate...failed.
** Saving server config key zimbraSSLPrivateKey...failed.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to /opt/zimbra/conf/ca...done.
Reply With Quote
  #10 (permalink)  
Old 03-26-2009, 09:37 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Follow all the instructions in this post: [SOLVED] Commercial cert Thawte
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.