Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 09-21-2010, 10:15 AM
Member
 
Posts: 14
Default [SOLVED] Zimbra & Outlook Self Signed Cert Error?

Hello all,

I think I have narrowed down my troubles for a remote user to that of certificate problems.

I have found what I believe to be the latest cert I created in this directory, /opt/zimbra/ssl/zimbra/ca/newcerts/. I have downloaded the .pem, renamed it to .crt so that I can import into the Windows Certificate store. It imports successfully, and I verify that the expiration date matches that of the one displayed in the Admin Console.

However, when I try and send an email from within Outlook with my mail server setup as an IMAP connection, I see the following error in my logs:

Code:
Sep 21 13:16:19 mail postfix/smtpd[8723]: lost connection after EHLO from (hostname removed) [ip removed]
I have disabled zimbraMtaTlsAuthOnly, and the account can send email fine. When it's set to TRUE I run into this problem, which is why I don't think Outlook is playing nicely with my certificates - even after I have imported them into Windows.

I'm at a loss here.

Any thoughts?

Thanks

Last edited by drsprite; 09-21-2010 at 10:33 AM..
Reply With Quote
  #2 (permalink)  
Old 09-22-2010, 08:22 AM
Member
 
Posts: 14
Default

Can anyone offer any help? I have a couple users who cannot access email through Outlook, and I think it may be a certificate error causing the disconnected on EHLO - but unsure.

Thanks
Reply With Quote
  #3 (permalink)  
Old 09-23-2010, 02:06 PM
Member
 
Posts: 14
Default

Anyone? Bueller?

I'm open to anything (except for using Thunderbird since that isn't an option of my clients).

Thanks
Reply With Quote
  #4 (permalink)  
Old 09-24-2010, 04:56 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Why don't you get them to use the correct Submission port of 587 (instead of port 25, which I assume is what you're currently using)? That will require Authentication to send mail.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 09-24-2010, 10:33 AM
Member
 
Posts: 14
Default

Thanks for the reply Bill. I will have him try port 587. As a word of note however, port 25 works for everyone else.

In case he continues to fail on port 587, any other suggestions?
Reply With Quote
  #6 (permalink)  
Old 09-24-2010, 10:59 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by drsprite View Post
Thanks for the reply Bill. I will have him try port 587. As a word of note however, port 25 works for everyone else.
They should all be using port 587 as it's the correct Submission port, port 25 is for an MTA to communicate with another MTA.

Quote:
Originally Posted by drsprite View Post
In case he continues to fail on port 587, any other suggestions?
Offhand I can't think of anything unless (a long shot) they have a firewall or ant-virus/anti-malware program that's scanning their mail ports or mail clients.
__________________
Regards


Bill
Reply With Quote
  #7 (permalink)  
Old 09-24-2010, 03:22 PM
Member
 
Posts: 14
Default

Awesome. port 587 worked great. You were right, once I put in port 587, Outlook finally had prompted me to accept the certificate.

Weird because I am seeing that on port 25 as well for other Outlook setups.

In any event, I won't question it. Thanks for the help
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.