Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 09-14-2009, 09:21 AM
Member
 
Posts: 11
Default [SOLVED] "zmcertmgr deploycrt self" Fails

My original 365 day self-signed certificate recently expired on my Zimbra 5.0.9 server. I followed the Zimbra wiki instructions to create a new set of certs as follows. I got most of the way through the process and then it failed. Any ideas on resolving this problem?

1. zmcertmgr createca -new
2. zmcertmgr createcrt -new -days 365
3. zmcertmgr deploycrt self

Steps 1 and 2 completed successfully. Step 3 completed partially and then failed.

** Saving server config key zimbraSSLCertificate...done.
** Saving server config key zimbraSSLPrivateKey...done.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...failed.

XXXXX ERROR: failed to create jetty.pkcs12
unable to load private key


From what I can tell, the mta, ldap, and proxy certs were created successfully, but the mailboxd cert failed to install. Here's what I get when I try to view the mailboxd cert.

zmcertmgr viewdeployedcrt mailboxd
::service mailboxd::
XXXXX ERROR: failed to export /opt/zimbra/mailboxd/etc/mailboxd.pem from keystore.

keytool error: java.lang.Exception: Alias <jetty> does not exist

unable to load certificate
20972:error:0D07207B:asn1 encoding routines:ASN1_get_object:header too long:asn1_lib.c:150:
notBefore=Aug 25 16:34:24 2007 GMT
notAfter=Aug 24 16:34:24 2009 GMT
subject= /C=US/ST=NA/L=NA/O=Zimbra/OU=Zimbra/CN=freedomics.com
issuer= /C=US/ST=NA/L=NA/O=Zimbra/OU=Zimbra/CN=freedomics.com
SubjectAltName=


Now my /opt/zimbra/mailboxd/etc/keystore file is only 32 bytes. Prior to this process it was 1339 bytes. I've been mucking around in the zmcertmgr bash script, but I'm not getting anywhere.

What just happened and what do I need to do to get my certs straightened out?
Reply With Quote
  #2 (permalink)  
Old 09-14-2009, 02:35 PM
Member
 
Posts: 11
Default

OK, after spending all day, I got this straightened out. Unfortunately, I can't pinpoint exactly what I did to fix the problem. Out of desparation, I downloaded a newer version of zmcertmgr (5.0.14) and temporarily changed the permissions of /opt/zimbra/ssl/etc/ to 777. This appears to have cleared up the problems with keytool failing.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.