| Welcome to the Zimbra :: Forums! | |
Welcome, if you would like to post a comment please register.
We also encourage you to explore all things Zimbra with our team and members of the community.
|  | 
07-05-2006, 08:16 AM
| | Special Member | |
Posts: 124
| | IMAP/POP/SMTP SSL Cert warning Clients using Mac-Mail, Outlook Express ( both on MAC and Windows ) and Thunderbird ( clients tested this far though I would suspect all of them would have this issue ) get the following warning every time they open/launch their client:
"The server you are connected to is using a security certificate that could not be verified.
A certificate chain processed correctly, but terminated in a root certificate which is not trusted by the trust provider.
Do you want to continue using this server
yes/no"
Now, realizing that self signed certs will do this, poked around on openssl and other sites to try to figure out how to export or make a root cert that I can add to the client machines to avoid that warning, work right, etc.,etc.
So, my question being: Can someone point me in the right direction, as to which cert I need to copy from the Zimbra server or cert I would need to create/export in order to add it to a client store to act as a root certifier?
Thanks in advance. :-)
Scotty
edit: Running 3.1.4 on FC4
Last edited by scottnelson; 07-05-2006 at 03:45 PM..
| 
07-07-2006, 12:04 PM
| | | I haven't tested this too much yet, but at least on the mac I was able to add it by doing the following:
1.) Have IMAP account setup in Mail.app.
2.) When the Cert window appears asking what to do, drag the actual "cert icon" off the window to your desktop.
3.) Double click the .cert file on your desktop and add it in with your keychain password.
*** You can double check that its in there by re-opening Mail.appl or Keychain Access. | 
09-07-2006, 05:22 PM
| | | Choose The Correct Keychain Quote: |
Originally Posted by cranch I haven't tested this too much yet, but at least on the mac I was able to add it by doing the following:
1.) Have IMAP account setup in Mail.app.
2.) When the Cert window appears asking what to do, drag the actual "cert icon" off the window to your desktop.
3.) Double click the .cert file on your desktop and add it in with your keychain password.
*** You can double check that its in there by re-opening Mail.appl or Keychain Access. | For 3.) above, likely the Mac user will have several keychains, and they will need to add the cert to the X.509 keychain to eliminate the certificate challenge going forward.
Mark | 
12-20-2006, 09:15 AM
| | Intermediate Member | |
Posts: 18
| | Quote:
Originally Posted by scottnelson Clients using Mac-Mail, Outlook Express ( both on MAC and Windows ) and Thunderbird ( clients tested this far though I would suspect all of them would have this issue ) get the following warning every time they open/launch their client:
"The server you are connected to is using a security certificate that could not be verified.
A certificate chain processed correctly, but terminated in a root certificate which is not trusted by the trust provider.
Do you want to continue using this server
yes/no"
Now, realizing that self signed certs will do this, poked around on openssl and other sites to try to figure out how to export or make a root cert that I can add to the client machines to avoid that warning, work right, etc.,etc.
So, my question being: Can someone point me in the right direction, as to which cert I need to copy from the Zimbra server or cert I would need to create/export in order to add it to a client store to act as a root certifier?
Thanks in advance. :-)
Scotty
edit: Running 3.1.4 on FC4 | I am running 4.04 NE on RHEL, when use thunderbird as client it give me a option the save the certificate permanently. But when use Outlook/OutlookExpress, this warning come up everytime I launch outlook. Is there a way to import and save the certificate in outlook?
Please advise. | 
12-20-2006, 09:27 AM
| | Zimbra Consultant & Moderator | |
Posts: 20,312
| | This is rather an old thread, it would have been better to start a new thread for this topic. Anyway, almost all of these answers should tell you the answer.
__________________
Regards
Bill
| 
12-20-2006, 10:14 AM
| | Intermediate Member | |
Posts: 18
| | Quote:
Originally Posted by phoenix This is rather an old thread, it would have been better to start a new thread for this topic. Anyway, almost all of these answers should tell you the answer. | Thanks very much | 
12-20-2006, 10:18 AM
| | Project Contributor | |
Posts: 203
| | root cert Quote:
Originally Posted by scottnelson Now, realizing that self signed certs will do this, poked around on openssl and other sites to try to figure out how to export or make a root cert that I can add to the client machines to avoid that warning, work right, etc.,etc.
So, my question being: Can someone point me in the right direction, as to which cert I need to copy from the Zimbra server or cert I would need to create/export in order to add it to a client store to act as a root certifier?
Thanks in advance. :-) | Probably late to this party, but thought I'd offer another bit on this...
I wrote a wiki page for how to get the root cert onto a Nokia phone which isn't relevant, but the part about converting it to DER format and putting it into a web accessible URL might be useful. http://wiki.zimbra.com/index.php?title=Nokia_E62
Double-clicking a .DER file on my mac will allow me to import it as an x509 anchor which makes the cert errors go away in Mail.app, etc
John | 
12-29-2006, 12:24 PM
| | Intermediate Member | |
Posts: 18
| | One more question Quote:
Originally Posted by phoenix This is rather an old thread, it would have been better to start a new thread for this topic. Anyway, almost all of these answers should tell you the answer. | by using your answer, I got rid of the certificate warning on receiving emails in outlook. But when I try to send email with SSL enabled SMTP, I still got the certificate warning. any idea how to over come this warning?
Thanks in advance. | | Thread Tools | Search this Thread | | | | | Display Modes | Linear Mode | | Why Join? Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.  |