Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-23-2010, 05:01 PM
Intermediate Member
 
Posts: 23
Default [SOLVED] CAcert certificate

hi all
today i want import a certificate from CAcert. i make it on the web, so i generate a csr, go to CAcert and generate a certifcate. i also download the root certifcate and the intermediate certificate. then i import all 3 .crt files (commercial.crt, cacert_root.crt, cacert_intermediate.crt) on the webgui but i only get this error:
Ihr Zertifikat konnte aufgrund eines Fehlers nicht installiert werden. : system failure: XXXXX ERROR: Unmatching certificate (/opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current.crt) and private key (/opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current_comm.key) pair.

What i make wrong? i have read some artikles with godaddy cert, but it dont want work. can someone give me a tip or help?
greetz
franco
Reply With Quote
  #2 (permalink)  
Old 07-25-2010, 05:16 AM
Intermediate Member
 
Posts: 23
Default

hi again
i have now installed a new commercial.crt. the verifying was ok, also the deploy. but when i now start zimbra i get this errors:
Code:
[zimbra@SMTP ~]$ zmcontrol start
Host smtp.network4kmu.at
	Starting ldap...Done.
Unable to determine enabled services from ldap.
Enabled services read from cache. Service list may be inaccurate.
	Starting logger...Failed.
Starting logswatch...ERROR: service.FAILURE (system failure: ZimbraLdapContext) (cause: javax.net.ssl.SSLHandshakeException sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target)
zimbra logger service is not enabled!  failed.


	Starting mailbox...Done.
	Starting antispam...Done.
	Starting antivirus...Done.
	Starting snmp...Done.
	Starting spell...Done.
	Starting mta...Done.
	Starting stats...Done.
so i have no webgui, what can i do. what is happen now? what is not correct?
greetz
franco
Reply With Quote
  #3 (permalink)  
Old 07-25-2010, 10:14 AM
j2b j2b is offline
Special Member
 
Posts: 109
Default

Did you run this:
# /opt/zimbra/java/bin/keytool -import -alias new -keystore /opt/zimbra/java/jre/lib/security/cacerts -storepass changeit -file /root/certs/commercial.crt

This is according to this thread:
http://www.zimbra.com/forums/adminis...rtificate.html
Reply With Quote
  #4 (permalink)  
Old 07-25-2010, 02:34 PM
Intermediate Member
 
Posts: 23
Default

hi j2b
thx for the tip, no i don't make this before. i would test it and give you answer. merci

greetz

franco
Reply With Quote
  #5 (permalink)  
Old 07-25-2010, 04:32 PM
Intermediate Member
 
Posts: 23
Default

hi j2b,
so i test your tip now, and what should i say? it WORKS perfectly now, cool thing. many great thx from me . and when someone can tell me how i can change the server that he only gets over https the webmail, then i am the happiest man in world

greetz

franco
Reply With Quote
  #6 (permalink)  
Old 07-26-2010, 12:06 AM
j2b j2b is offline
Special Member
 
Posts: 109
Default

Welcome! Just was dealing with this item for last two days, looking for info. Regarding your other question - is this correct, what you would like to achieve - allow connections to zimbra web client only on SSL (https)? If so, what is your setup? One server / Multiserver. Do you use Zimbra proxy or other solutions or no proxy at all?
Reply With Quote
  #7 (permalink)  
Old 07-26-2010, 01:11 AM
j2b j2b is offline
Special Member
 
Posts: 109
Default

Sorry, looking through your first post, it seems, that you have single server installation, but with no proxy server. To make my former question more specific, do you use any kind of proxy before ZCS server to access it via web client? Or you ar connecting to ZCS server directly?
Reply With Quote
  #8 (permalink)  
Old 07-26-2010, 02:35 AM
Intermediate Member
 
Posts: 23
Default

hi j2b
i use a single server with direct connection, over firewall (monowall). i want webmail only on https available. can i do that with zimbra? no i do not use a proxy server because it is a one man show

greetz

franco
Reply With Quote
  #9 (permalink)  
Old 07-26-2010, 11:10 AM
Intermediate Member
 
Posts: 23
Default

ok i found the command, zmtlsctl redirect is what i want, many thx for great helping!

greetz

franco
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.