Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-17-2010, 06:28 AM
Loyal Member
 
Posts: 82
Default Can't start Zimbra MTA

Dear experts,
I have two server: one for mailbox server and one for MTA Server. The system is running ok but today, I see that I can't start Zimbra on MTA Server. Each time I try to start, Zimbra said that:
"Host mailmta.domain.com
Unable to determine enabled services from ldap.
Unable to determine enabled services. Cache is out of date or doesn't exist."

I have checked everything about hosts file, resolv.conf file, dns, ... and there are no problem. When I try to update key by zmupdateauthkeys on MTA server, I see the following error: "ERROR: service.FAILURE (system failure: ZimbraLdapContext) (cause: javax.net.ssl.SSLHandshakeException sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: signature check failed)".
Please help me to resolve it.

Thank you so much!
Reply With Quote
  #2 (permalink)  
Old 01-17-2010, 06:48 AM
Zimbra Consultant & Moderator
 
Posts: 20,312
Default

You should try a search before posting a question, search the forums for the words 'PKIX path validation failed'.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 01-14-2011, 10:12 PM
Junior Member
 
Posts: 6
Default

I had similler problem my certifacte was expired. It happend exactly after 1 year. Try to recreate certs.

I did following thing as root

chown -R zimbra:zimbra /opt/zimbra

/opt/zimbra/libexec/zmfixperms -verbose

/opt/zimbra/bin/zmcertmgr createca -new
/opt/zimbra/bin/zmcertmgr createcrt -new -days 365
/opt/zimbra/bin/zmcertmgr deploycrt self
/opt/zimbra/bin/zmcertmgr deployca

Above command might give below error.
** Saving global config key zimbraCertAuthorityCertSelfSigned...failed.
** Saving global config key zimbraCertAuthorityKeySelfSigned...failed.


Restart the services:

su - zimbra -c "zmcontrol stop"
su - zimbra -c "zmcontrol start"

and reenter the command to deploy the certificate on ldap: this time it should not give any error

/opt/zimbra/bin/zmcertmgr deploycrt self
/opt/zimbra/bin/zmcertmgr deployca
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.