Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 10-15-2010, 05:51 AM
Active Member
 
Posts: 26
Default Zimbra SSL Certificate Issue

Hi,

I have been using zimbra 6.0.x for a year, today it stopped working. On zmprov it gave PKIX path validation failed, failed to check timestamp. On running zmcontrol start it starts ldap with message being.

Unable to determine enabled services from ldap. Enabled services read from cache. Service list may be inaccurate.

I tried re-creating the certificates. through the following:
1.zmcertmgr createca -new
worked fine
2.zmcertmgr createcrt -new -days 365
one failure message regarding:
Saving server config key zimbraSSLPrivateKey--failed
3. zmcertmgr deploycrt self
Saving server config key zimbraSSLCertificate--failed
Saving server config key zimbraSSLPrivateKey--failed


Your help is eagerly awaited.

Thanks !
Abhishek
Reply With Quote
  #2 (permalink)  
Old 10-15-2010, 06:00 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

A forum search for the error would get you the following results: site:zimbra.com +"Saving server config key zimbraSSLCertificate--failed" - Yahoo! Search Results - take your pick of the solutions.

I'll move this to the correct forum as it's not a 'User' question.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 10-15-2010, 06:17 AM
Active Member
 
Posts: 26
Default

Thanks for putting this in appropriate forum. I have been fighting on this for whole day on google search but no luck

Your expertise will go a long way in bringing back our users on email.

Abhishek
Reply With Quote
  #4 (permalink)  
Old 11-20-2010, 09:56 AM
Junior Member
 
Posts: 7
Default

Quote:
Originally Posted by kumabhi View Post
I have been using zimbra 6.0.x for a year, today it stopped working. On zmprov it gave PKIX path validation failed, failed to check timestamp. On running zmcontrol start it starts ldap with message being.

Unable to determine enabled services from ldap. Enabled services read from cache. Service list may be inaccurate.

I tried re-creating the certificates. through the following:
1.zmcertmgr createca -new
worked fine
2.zmcertmgr createcrt -new -days 365
one failure message regarding:
Saving server config key zimbraSSLPrivateKey--failed
3. zmcertmgr deploycrt self
Saving server config key zimbraSSLCertificate--failed
Saving server config key zimbraSSLPrivateKey--failed
I'm having the same trouble. Creating new certs just errors. Any thoughts?

Mike
Reply With Quote
  #5 (permalink)  
Old 11-20-2010, 09:58 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by eldon96 View Post
I'm having the same trouble. Creating new certs just errors. Any thoughts?
What about trying some of the solutions in the link I posted above?
__________________
Regards


Bill
Reply With Quote
  #6 (permalink)  
Old 11-20-2010, 10:19 AM
Active Member
 
Posts: 26
Default

I used this Ajcody-Notes-SSLCerts - Zimbra :: Wiki
Please see if it helps you.
Reply With Quote
  #7 (permalink)  
Old 11-22-2010, 10:51 AM
Junior Member
 
Posts: 7
Default

Well, I looked through the solutions that the yahoo search above came up with - to no avail. I did end up finding something that helped.

[SOLVED] SOLVED: Zimbra 6.0.1 stop working if SSL certificate is expired

in combination with

Recreating a Self-Signed SSL Certificate in ZCS 4.5 & 5.0 - Zimbra :: Wiki

The step listed by Eaperezh initially failed but the wiki was far too involved for what I was wanting to do. So, comparing the two solutions revealed what to do. Doing the steps listed by Eaperezh in the order of 1, 4, 2, 3, then doing the LDAP step that he listed at the bottom solved my cert issue.

I do have one thought that I'll worry about next year. Eaperezh says to create the cert with the -days 365 switch but the wiki doesn't mention setting a day count. If I had left the -days 365 off, would it have created a cert that would have never expired?

Mike
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.