Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-07-2010, 08:17 AM
Elite Member
 
Posts: 380
Default Does the SSL cert on the Zimbra server's Primary Name need to match the server name?

For Zimbra itself to be happy, I mean; it's looking like I need to have the cert be named after what my iPhones are going to want to call it in order for *them* to work -- and Apple explicitly doesn't support anything but Genuine Microsoft Exchange.

So the question is: does *Zimbra* require that the server's idea of its own name appear in the SSL cert that it servers? If so, can it be a secondary name?
__________________
Jay R. Ashworth - ZCS 6.0.9CE/CentOS5 - St Pete FL US - Music - Blog - Photography - IANAL - IAAMA
Try to Ask Questions The Smart Way -- you'll get better answers.

Put your product and version in your profile/signature - All opinions strictly my own, even though I have an employer these days.
If you [SOLVE] something, please tell everyone how for the archives
And, please... read what people write, and answer the questions they asked, not the ones they didn't.
Reply With Quote
  #2 (permalink)  
Old 04-07-2010, 08:52 AM
Moderator
 
Posts: 7,928
Default

Hi, not really following. Within the iPhone settings you would enter the FQDN of your Zimbra server; for which should match the CN of the cert. If it does not then the iPhone just asks if you wish to accept it (especially if you are using a self signed cert).
__________________
Reply With Quote
  #3 (permalink)  
Old 04-07-2010, 09:07 AM
Elite Member
 
Posts: 380
Default

See my other thread, just updated. Apple *requires* that the primary name on the cert -- self signed or not -- be *the name the phone uses to get to EAS*.

Hence, I have to rebuild my cert to do this, with async.mumble as its primary name.

Hence my question above.
__________________
Jay R. Ashworth - ZCS 6.0.9CE/CentOS5 - St Pete FL US - Music - Blog - Photography - IANAL - IAAMA
Try to Ask Questions The Smart Way -- you'll get better answers.

Put your product and version in your profile/signature - All opinions strictly my own, even though I have an employer these days.
If you [SOLVE] something, please tell everyone how for the archives
And, please... read what people write, and answer the questions they asked, not the ones they didn't.
Reply With Quote
  #4 (permalink)  
Old 04-07-2010, 09:14 AM
Moderator
 
Posts: 7,928
Default

I am guessing it will be fine. We have our own PKI and use a combination ZCS FQDN, Alternative name and IP address.
__________________
Reply With Quote
  #5 (permalink)  
Old 04-07-2010, 10:25 AM
Elite Member
 
Posts: 380
Default

But the primary name on your certs is the "real" configured name of your server? Or an alias?

Cause if the iPhones require their name to be primary, and Zimbra requires *its*, then I'm either going to have to rename the server, or play games with my DNS.
__________________
Jay R. Ashworth - ZCS 6.0.9CE/CentOS5 - St Pete FL US - Music - Blog - Photography - IANAL - IAAMA
Try to Ask Questions The Smart Way -- you'll get better answers.

Put your product and version in your profile/signature - All opinions strictly my own, even though I have an employer these days.
If you [SOLVE] something, please tell everyone how for the archives
And, please... read what people write, and answer the questions they asked, not the ones they didn't.
Reply With Quote
  #6 (permalink)  
Old 04-09-2010, 09:10 AM
Elite Member
 
Posts: 380
Default

In either event, having had it confirmed by Quanah on my bug ticket that in fact, it's not supposed to care, I ran AJ's "build your own self-signed cert" script, modified like so:

Code:
/opt/zimbra/bin/zmcertmgr createcrt self -new -subject "C=US/ST=N\/A/L=N\/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=async.mumble" -subjectAltNames "benjamin.mumble,zmail.mumble"
And, of course, for some reason, when I look in the admin console it doesn't appear to have actually done *anything*; my cert is still for benjamin.mumble, with no altNames.

Confused, now.
__________________
Jay R. Ashworth - ZCS 6.0.9CE/CentOS5 - St Pete FL US - Music - Blog - Photography - IANAL - IAAMA
Try to Ask Questions The Smart Way -- you'll get better answers.

Put your product and version in your profile/signature - All opinions strictly my own, even though I have an employer these days.
If you [SOLVE] something, please tell everyone how for the archives
And, please... read what people write, and answer the questions they asked, not the ones they didn't.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.