Results 1 to 5 of 5

Thread: [SOLVED] Zimbra SSL Certificates Expired

  1. #1
    madods is offline New Member
    Join Date
    Sep 2009
    Posts
    3
    Rep Power
    5

    Default [SOLVED] Zimbra SSL Certificates Expired

    Hi,

    My self signed Zimbra SSL certificates have expired, and the effect is I cannot start Zimbra at all:

    $ ./zmcontrol startup
    Host [fqdn]
    Starting ldap...Done.
    Unable to determine enabled services from ldap.
    Unable to determine enabled services. Cache is out of date or doesn't exist.

    I found this thread in the forums:

    [SOLVED] Certificate Expire problem - A network service error has occurred.

    Which pointed me to:
    Recreating a Self-Signed SSL Certificate in ZCS 4.5 & 5.0 - Zimbra :: Wiki

    but that is for version 4.5 and 5.0 whereas I am running:

    Release 6.0.0_GA_1802.UBUNTU8 UBUNTU8 FOSS edition.

    There is a link to:

    Administration Console and CLI Certificate Tools - Zimbra :: Wiki

    which applies to version 6.0 but I'm unsure of what I need to do. Do I need to recreate a whole new CA and all certificates, or do I just create new certificates in the existing CA?

    Is there a detailed document for doing this in V6.0 that I've missed?

  2. #2
    uxbod's Avatar
    uxbod is offline Moderator
    Join Date
    Nov 2006
    Location
    UK
    Posts
    8,017
    Rep Power
    24

    Default

    Welcome to the forums

    You should just be able to do the following as root
    Code:
    zmcertmgr deploycrt self -new

  3. #3
    madods is offline New Member
    Join Date
    Sep 2009
    Posts
    3
    Rep Power
    5

    Default

    Quote Originally Posted by uxbod View Post
    Welcome to the forums

    You should just be able to do the following as root
    Code:
    zmcertmgr deploycrt self -new
    Thanks for the welcome.

    Wow, that's considerably simpler than I expected from the solutions for older versions!

    I looked that command up in the Administration Console and CLI Certificate Tools - Zimbra :: Wiki document. (The -new option isn't listed in the deploycrt section.) It seems that new certificates would be created using the existing CA. Is that correct?

    Does that zmcertmgr command take care of all the removal of the certificates from the various keystores that are included in the instructions in the Recreating a Self-Signed SSL Certificate in ZCS 4.5 & 5.0 - Zimbra :: Wiki document?

  4. #4
    uxbod's Avatar
    uxbod is offline Moderator
    Join Date
    Nov 2006
    Location
    UK
    Posts
    8,017
    Rep Power
    24

    Default

    Here is a complete step by step Ajcody-Notes-SSLCerts - Zimbra :: Wiki

  5. #5
    madods is offline New Member
    Join Date
    Sep 2009
    Posts
    3
    Rep Power
    5

    Default

    Quote Originally Posted by uxbod View Post
    Here is a complete step by step Ajcody-Notes-SSLCerts - Zimbra :: Wiki
    Excellent! That's what I was looking for. Thanks for the help.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. /tmp filling
    By Nutz in forum Administrators
    Replies: 8
    Last Post: 02-22-2008, 02:00 AM
  2. zmtlsctl give LDAP error
    By sourcehound in forum Administrators
    Replies: 5
    Last Post: 03-11-2007, 03:48 PM
  3. huge log size
    By rmvg in forum Administrators
    Replies: 5
    Last Post: 01-02-2007, 10:39 AM
  4. Fedora Core 3, Clean Install - Not working!
    By pcjackson in forum Installation
    Replies: 17
    Last Post: 03-05-2006, 07:38 PM
  5. Monitoring : Data not yet avalaible
    By s3nz3x in forum Installation
    Replies: 7
    Last Post: 11-30-2005, 07:18 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •