The command must run by root.
Code:
cd /opt/zimbra
mv ssl ssl.backup
mkdir ssl
chown -R zimbra:zimbra ./ssl
/opt/zimbra/bin/zmcertmgr createca -new
/opt/zimbra/bin/zmcertmgr createcrt -new -days 365
/opt/zimbra/bin/zmcertmgr deploycrt self
/opt/zimbra/bin/zmcertmgr deployca
#######restart zimbra services with user zimbra ####
su zimbra
zmcontrol stop
zmcontrol start
exit
cd /opt/zimbra/ssl/zimbra/ca
openssl x509 -in ca.pem -out cert.der -outform DER
Enjoy now you have valid client .der cert for 1 Y.