Results 1 to 5 of 5

Thread: ZimbraSSLPrivateKey failed after deploying certs

  1. #1
    vtx624 is offline Intermediate Member
    Join Date
    Jan 2009
    Posts
    24
    Rep Power
    6

    Default ZimbraSSLPrivateKey failed after deploying certs

    Zimbra,

    I get this message when I try to deploy one of my certs

    **Saving server config key zimbraSSLPrivateKey…failed.

    How do I go about resolving this issue.


    Code:
    ** Verifying /opt/tmp/new_cert2009/test_cert/ssl.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
    Certificate (/opt/tmp/new_cert2009/test_cert/ssl.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
    Valid Certificate: /opt/tmp/new_cert2009/test_cert/ssl.crt: OK
    ** Copying /opt/tmp/new_cert2009/test_cert/ssl.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
    ** Appending ca chain /opt/tmp/new_cert2009/test_cert/ca.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
    ** Saving server config key zimbraSSLCertificate...done.
    ** Saving server config key zimbraSSLPrivateKey...failed.
    ** Installing mta certificate and key...done.
    ** Installing slapd certificate and key...done.
    ** Installing proxy certificate and key...done.
    ** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
    ** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
    ** Installing CA to /opt/zimbra/conf/ca...done.
    By the way I'm using startssl certs

    Any help would be appreciated
    Last edited by vtx624; 10-13-2009 at 05:44 PM.

  2. #2
    vtx624 is offline Intermediate Member
    Join Date
    Jan 2009
    Posts
    24
    Rep Power
    6

    Default

    I've search around the forums and People have provided this information.

    I am also using a DRBD and heartbeat setup. I have not restarted yet in fear that zimbra won't start.

    Does anyone have a clue?

    Thanks

    Here is my vi/etc/hosts
    Code:
    127.0.0.1       localhost.localdomain localhost
    10.1.200.62     mail-1.example.com        mail-1
    10.1.200.57     mail-2.example.com        mail-2
    10.1.200.62     mail.example.com          mail

    hostname `hostname`

    Code:
    mail-1.example.com has address 10.1.200.62

    dig

    Code:
    ; <<>> DiG 9.3.4-P1.1 <<>> mx example.com
    ;; global options:  printcmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12500
    ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 1, ADDITIONAL: 2
    
    ;; QUESTION SECTION:
    ;example.com.             IN      MX
    
    ;; ANSWER SECTION:
    example.com.      2592000 IN      MX      10 mail.example.com.
    
    ;; AUTHORITY SECTION:
    example.com.      2592000 IN      NS      mail-2.example.com.
    
    ;; ADDITIONAL SECTION:
    mail.example.com. 2592000 IN      A       10.1.200.13
    
    
    ;; Query time: 0 msec
    ;; SERVER: 10.1.200.57#53(10.1.200.57)
    ;; WHEN: Tue Oct 13 18:05:37 2009
    ;; MSG SIZE  rcvd: 133
    Last edited by vtx624; 10-13-2009 at 07:46 PM.

  3. #3
    vtx624 is offline Intermediate Member
    Join Date
    Jan 2009
    Posts
    24
    Rep Power
    6

    Default

    I have tried editing all both hosts and hostname with mail.vertextelecom on 10.1.200.62. I also changed the DNS entry to that. It did not not work.

  4. #4
    vtx624 is offline Intermediate Member
    Join Date
    Jan 2009
    Posts
    24
    Rep Power
    6

    Default

    I have restarted the services and it seems to have come up just fine. Does anyone know what services are affected by the zimbraSSLPrivatekey.

    Thanks

  5. #5
    markd is offline Intermediate Member
    Join Date
    Jul 2009
    Posts
    16
    Rep Power
    5

    Default same error but works

    Have similar situation.

    Saving server config key zimbraSSLCertificate...failed.
    Saving server config key zimbraSSLPrivateKey...failed.

    Note, I was deploying the certs while zimbra was not running,
    does that have any effect.

    After starting zimbra, so no errors. Admin console for certificates
    appears to show everything correct. I don't see any immediate
    side effects, yet.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. [SOLVED] Zimbra logwatch.
    By nishith in forum Administrators
    Replies: 5
    Last Post: 06-10-2009, 04:42 PM
  2. Help!!! Moving ZCS does not work!
    By ASebestian in forum Migration
    Replies: 7
    Last Post: 02-12-2009, 06:06 PM
  3. Problem with Mail Server - Need help!
    By joeleo in forum Installation
    Replies: 2
    Last Post: 03-04-2008, 12:03 PM
  4. My Zimbra server down ... please help :)
    By frankb in forum Administrators
    Replies: 2
    Last Post: 12-12-2007, 11:29 AM
  5. Lotus migration
    By babou in forum Migration
    Replies: 15
    Last Post: 03-05-2007, 10:33 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •