Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 11-05-2009, 05:00 AM
Junior Member
 
Posts: 7
Default StartSSL Free SSL Certificate + Zimbra

Hi,

I was just wondering if anyone had any experience with the free non-selfsigned StartSSL certificates from StartSSLâ„¢ Certificates & Public Key Infrastructure.

Can they be easily be loaded into zimbra and how does it work?

Thanks,
Deniz
Reply With Quote
  #2 (permalink)  
Old 11-21-2009, 11:15 AM
Member
 
Posts: 14
Default

I was able to import it, but despite the import procedure went fine it looks like the certificate is not working correctly, and SSL services aren't started.
Reply With Quote
  #3 (permalink)  
Old 07-29-2010, 11:01 AM
New Member
 
Posts: 4
Lightbulb StartSSL Instructions

Installing a StartSSL SSL Certificate with zmcertmgr - Zimbra :: Wiki
Reply With Quote
  #4 (permalink)  
Old 04-05-2011, 09:05 AM
Special Member
 
Posts: 103
Default

I've never been able to get the basic StartSSL cert to work with Zimbra. I don't know if it's me, or if it's StartSSL, but I get the following message when installing it via the CLI:

Code:
XXXXX ERROR: Unmatching certificate (/tmp/ssl.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) pair.
XXXXX ERROR: provided cert isn't valid.
And the following message when installing it via the admin console:

Code:
Message: invalid request: missing required attribute: server Error code: service.INVALID_REQUEST Method: GetCertRequest Details:soap:Sender
As far as I know, I'm doing everything correct. I generated a new certificate signing request via the admin console, give the CSR to StartSSL (which they like), and they generate a certificate for me.

My hunch is that the problem lies with the way my Zimbra server is named. The server itself is named friendlyname.ourdomain.com, but the certificate needs to be for mail.ourdomain.com.

When generating the CSR, I specify "mail.ourdomain.com" as the common name. Should it be a Subject Alternative Name instead....or both?

Or, perhaps, it is a StartSSL problem as "All content of the certificate signing request is ignored except its public key."?

We used to use ipsCA certs and never had an issue (until their CA cert expired)...
Reply With Quote
  #5 (permalink)  
Old 04-06-2011, 04:14 PM
Special Member
 
Posts: 118
Default

Works fine for me, but remember to remove the pass phrase from the cert before installing or you'll have problems
Reply With Quote
  #6 (permalink)  
Old 04-07-2011, 08:15 AM
Special Member
 
Posts: 103
Default

If you use the Zimbra generated CSR, there shouldn't be a password??
Reply With Quote
  #7 (permalink)  
Old 04-07-2011, 08:32 AM
Special Member
 
Posts: 118
Default

I must not have used the Zimbra CSR then
Reply With Quote
  #8 (permalink)  
Old 04-07-2011, 11:51 AM
Active Member
 
Posts: 30
Default

Quote:
My hunch is that the problem lies with the way my Zimbra server is named. The server itself is named friendlyname.ourdomain.com, but the certificate needs to be for mail.ourdomain.com.

When generating the CSR, I specify "mail.ourdomain.com" as the common name. Should it be a Subject Alternative Name instead....or both?
No idea if that's the problem, but if you need to support multiple hostnames in the same certificate you need a class 2 cert ($49) not their free class 1 cert.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.