Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 10-03-2010, 03:00 AM
New Member
 
Posts: 3
Default [SOLVED] Zimbra SSL Certificates Expired

Hi,

My self signed Zimbra SSL certificates have expired, and the effect is I cannot start Zimbra at all:

$ ./zmcontrol startup
Host [fqdn]
Starting ldap...Done.
Unable to determine enabled services from ldap.
Unable to determine enabled services. Cache is out of date or doesn't exist.

I found this thread in the forums:

[SOLVED] Certificate Expire problem - A network service error has occurred.

Which pointed me to:
Recreating a Self-Signed SSL Certificate in ZCS 4.5 & 5.0 - Zimbra :: Wiki

but that is for version 4.5 and 5.0 whereas I am running:

Release 6.0.0_GA_1802.UBUNTU8 UBUNTU8 FOSS edition.

There is a link to:

Administration Console and CLI Certificate Tools - Zimbra :: Wiki

which applies to version 6.0 but I'm unsure of what I need to do. Do I need to recreate a whole new CA and all certificates, or do I just create new certificates in the existing CA?

Is there a detailed document for doing this in V6.0 that I've missed?
Reply With Quote
  #2 (permalink)  
Old 10-04-2010, 02:16 AM
Moderator
 
Posts: 7,928
Default

Welcome to the forums

You should just be able to do the following as root
Code:
zmcertmgr deploycrt self -new
__________________
Reply With Quote
  #3 (permalink)  
Old 10-04-2010, 02:30 AM
New Member
 
Posts: 3
Default

Quote:
Originally Posted by uxbod View Post
Welcome to the forums

You should just be able to do the following as root
Code:
zmcertmgr deploycrt self -new
Thanks for the welcome.

Wow, that's considerably simpler than I expected from the solutions for older versions!

I looked that command up in the Administration Console and CLI Certificate Tools - Zimbra :: Wiki document. (The -new option isn't listed in the deploycrt section.) It seems that new certificates would be created using the existing CA. Is that correct?

Does that zmcertmgr command take care of all the removal of the certificates from the various keystores that are included in the instructions in the Recreating a Self-Signed SSL Certificate in ZCS 4.5 & 5.0 - Zimbra :: Wiki document?
Reply With Quote
  #4 (permalink)  
Old 10-04-2010, 02:38 AM
Moderator
 
Posts: 7,928
Default

Here is a complete step by step Ajcody-Notes-SSLCerts - Zimbra :: Wiki
__________________
Reply With Quote
  #5 (permalink)  
Old 10-04-2010, 02:44 AM
New Member
 
Posts: 3
Default

Quote:
Originally Posted by uxbod View Post
Here is a complete step by step Ajcody-Notes-SSLCerts - Zimbra :: Wiki
Excellent! That's what I was looking for. Thanks for the help.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.