Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-16-2010, 10:42 AM
Intermediate Member
 
Posts: 18
Question [SOLVED] Installing GoDaddy SSL Cert in Zimbra 6.0.7

I generated a CSR request from within the Zimbra admin GUI and have downloaded a Zip file from GoDaddy that contains gd_bundle, gd_cross_intermediate, gd_intermediate and xxx.domain.com

I am trying to install in the admin GUI but it's not clear which files to install where.

I am asked for files for these three locations. Certificate: Root CA: and Intermediate CA:

Can anyone provide assistance as to what I need to plugin and where?

Reply With Quote
  #2 (permalink)  
Old 06-16-2010, 10:51 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Try some of the solutions in these threads: site:zimbra.com +godaddy +solved - Yahoo! Search Results
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 06-16-2010, 12:02 PM
Trained Alumni
 
Posts: 46
Default

Easiest way- forget the GUI.

All you need from GD is gd_bundle. Make sure the keyfile you want to go with the cert is copied to /opt/zimbra/ssl/zimbra/commercial as commercial.key, then run (as root):

/opt/zimbra/bin/zmcertmgr deploycrt comm <mycertfile> <gd_bundle>
Reply With Quote
  #4 (permalink)  
Old 06-16-2010, 12:49 PM
Intermediate Member
 
Posts: 18
Default

O.K. but how do I determine the correct keyfile? i.e. <mycertfile>
And do I use the Tomcat or Apache files from GD?

Thanks!
Reply With Quote
  #5 (permalink)  
Old 06-16-2010, 12:59 PM
Trained Alumni
 
Posts: 46
Default

the keyfile goes along with the csr request- so if you generated a commercial csr from zimbra, the commercial.key should already be in the right place for you.

You shouldn't need to worry about the tomcat/apache services.
Reply With Quote
  #6 (permalink)  
Old 06-16-2010, 01:35 PM
Intermediate Member
 
Posts: 18
Default

Well it appears that key isn't valid. How did that happen?

/opt/zimbra/bin/zmcertmgr deploycrt comm /usr/local/src/CERTIFICATE_GODADDY/gd_bundle.crt
** Verifying /usr/local/src/CERTIFICATE_GODADDY/gd_bundle.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
XXXXX ERROR: Unmatching certificate (/usr/local/src/CERTIFICATE_GODADDY/gd_bundle.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) pair.
XXXXX ERROR: provided cert isn't valid.
Reply With Quote
  #7 (permalink)  
Old 06-16-2010, 01:42 PM
Advanced Member
 
Posts: 205
Default

Did you pull the TOMCAT, or Apache?

I had problems with the Apache key when I last update my GD cert, but the Tomcat one went in ok via the CLI interface.
Reply With Quote
  #8 (permalink)  
Old 06-16-2010, 01:45 PM
Intermediate Member
 
Posts: 18
Default

I've tried them both with the same result.
Reply With Quote
  #9 (permalink)  
Old 06-16-2010, 02:42 PM
Trained Alumni
 
Posts: 46
Default

Quote:
Originally Posted by tbarhorst View Post
Well it appears that key isn't valid. How did that happen?

/opt/zimbra/bin/zmcertmgr deploycrt comm /usr/local/src/CERTIFICATE_GODADDY/gd_bundle.crt
** Verifying /usr/local/src/CERTIFICATE_GODADDY/gd_bundle.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
XXXXX ERROR: Unmatching certificate (/usr/local/src/CERTIFICATE_GODADDY/gd_bundle.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) pair.
XXXXX ERROR: provided cert isn't valid.
You should be verifying your certificate against the commercial key, not godaddy's bundle. The zmcertmgr command line needs both your cert and godaddy's to work- zmcertmgr deploycrt comm <mycert> <godaddycert>
Reply With Quote
  #10 (permalink)  
Old 06-17-2010, 07:59 AM
Intermediate Member
 
Posts: 18
Default

Still get the same error.. I'm not at all sure where to go from here.


/opt/zimbra/bin/zmcertmgr deploycrt comm /opt/zimbra/ssl/zimbra/commercial/commercial.key /usr/local/src/CERTIFICATE_GODADDY/gd_bundle.crt
** Verifying /opt/zimbra/ssl/zimbra/commercial/commercial.key against /opt/zimbra/ssl/zimbra/commercial/commercial.key
unable to load certificate
17798:error:0906D06C:PEM routines:PEM_read_bio:no start lineem_lib.c:650:Expecting: TRUSTED CERTIFICATE
XXXXX ERROR: Unmatching certificate (/opt/zimbra/ssl/zimbra/commercial/commercial.key) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) pair.
XXXXX ERROR: provided cert isn't valid.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.