Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-07-2010, 01:24 AM
Member
 
Posts: 14
Default [SOLVED] zmprov not working after unsuccessful cert installation

I was using a self cert and was trying to install a new certificate from CAroot. I was following the instruction in wiki and ain't sure which step I did wrong. So, I tried re-gen a self cert again and found saving SSL Key failed. In fact, I found zmprov fail to work altogether.

[root@mailserv ~]# /opt/zimbra/bin/zmcertmgr createcrt self -new
** Creating /opt/zimbra/conf/zmssl.cnf...done
** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20100107170839
** Retrieving server config key zimbraSSLCertificate...failed.
** Retrieving server config key zimbraSSLPrivateKey...failed.
** Generating a server csr for download self -keysize 1024
** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20100107170845
** Creating server cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.
** Saving server config key zimbraSSLPrivateKey...failed.
** Signing cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.

[zimbra@mailserv ~]$ zmprov -l gcf zimbraCertAuthorityKeySelfSigned
ERROR: service.FAILURE (system failure: ZimbraLdapContext) (cause: javax.net.ssl.SSLHandshakeException sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: signature check failed)

Now, I think I am in deep trouble. The zimbra server is still running fine but I am so afraid if I have to reboot at some point and found everything is gone. Can someone please help to point out how to fix the zmprove failure?

Thank you very much.
Reply With Quote
  #2 (permalink)  
Old 01-08-2010, 04:02 AM
Member
 
Posts: 14
Default

Well actually, as it turn out, I follow the instructions in
Recreating a Self-Signed SSL Certificate - Zimbra :: Wiki
correctly. But the only thing is, I found that after new certificate installation, zmprov will not work until zmcontrol stop and restart. However, since the instructions in wiki instruct to use zmprov to verify the cacert right after "zmcertmgr deploycrt". This scared the daylight out of me to find zmprov suddenly stop working.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.