Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-10-2010, 04:05 AM
Senior Member
 
Posts: 55
Unhappy [SOLVED] Problem with certificate renew

Dear All,

I renewed my certificate with the same information the last certificate and
my browse give to me this warning.
"The security certificate presented by this website was issued for a different website´s address."

My configuration is showed below.
server name: mailhost.mydomain.com.br
webmail URL: webmail.mydomain.com.br

I checked my Subject: CN in my certificate and it is correct. What´s wrong?
I show the command output below.

[root@mailhost commercial]# /opt/zimbra/openssl/bin/openssl x509 -text -in commercial.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 534497 (0x827e1)
Signature Algorithm: sha1WithRSAEncryption
Issuer: O=Root CA, OU=http://www.cacert.org, CN=CA Cert Signing Authority/emailAddress=support@cacert.org
Validity
Not Before: Feb 4 11:41:21 2010 GMT
Not After : Aug 3 11:41:21 2010 GMT
Subject: CN=webmail.mydomain.com.br
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public Key: (1024 bit)
Modulus (1024 bit):
xx:XX:XX:XX:XX:XX:XX
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Extended Key Usage:
TLS Web Client Authentication, TLS Web Server Authentication, Netscape Server Gated Crypto, Microsoft Server Gated Crypto
X509v3 Key Usage:
Digital Signature, Key Encipherment
Authority Information Access:
OCSP - URI:http://ocsp.cacert.org/

X509v3 Subject Alternative Name:
DNS:mailhost.mydomain.com.br, DNS:ns.mydomain.com.br
Signature Algorithm: sha1WithRSAEncryption
xxxxx...

Best regards,
Bibo
Reply With Quote
  #2 (permalink)  
Old 02-12-2010, 03:13 AM
Senior Member
 
Posts: 55
Default

Hi All,

When you use the Subject Alternative Name (SAN) you must add the CN in the SAN. I have added and I resolved my problem. In that case my SAN was
Subject Alternative Name:
DNS:mailhost.mydomain.com.br, DNS:webmail.mydomain.com.br


Best regards,
Bibo
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.