Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 11-03-2010, 06:44 PM
Loyal Member
 
Posts: 97
Exclamation New GeoTrust SSL certificates and Android users

Since GeoTrust / Thawte decided to have some fun this year and replace their Root CA, handling SSL certificate upgrades/renewals/requests for Tomcat/Apache/Jetty/Zimbra users have become somewhat more painful.

Apart from being filled with (sometimes) confusing hints on how to solve this, merging a root CA with an intermediate CA, there is very little talk both here and in other places about how to solve the rather burning issue of Android phones not being able to connect to a Zimbra server secured with a new GeoTrust / Thawte certificate.

The problem is with getting Android to "believe" in the CA presented in these new certificates. There are threads everywhere to the effect of "Simply combine the proper root CA from GeoTrust / Thawte and then add your intermediate CA and then deploy your new certificate" (and Bob's your uncle).

The only problem is that this doesn't work for Android users.

IMAP over SSL is not working (certificate error)
Exchange ActiveSync over SSL is not working (certificate error)

Are we the only ones that have run into this problem and not having been able to solve it?



-joho
Reply With Quote
  #2 (permalink)  
Old 11-19-2010, 07:44 AM
Intermediate Member
 
Posts: 16
Default

Yup, I too am having this problem. I just updated my Verisgn key to the new-ish VeriSign Class 3 Secure Server CA G2 cert and it poofied my android phones as well as my Zimbra Desktops. My Zimbra Desktops say that the cert is invalid or not trusted. Once a few of my iphone people get in I will test those too. Chrome and Firefox are fine and dandy with the new cert.
Reply With Quote
  #3 (permalink)  
Old 11-19-2010, 11:17 AM
Intermediate Member
 
Posts: 16
Default

Iphones appear to be just fine with the new cert just like my web browsers. Androids and ZD hate the new cert.
Reply With Quote
  #4 (permalink)  
Old 11-21-2010, 11:34 AM
Trained Alumni
 
Posts: 343
Default

Ditto. We just put one of the new 2048 bit Geotrust certs on our Zimbra servers and Android is broken. Just adding myself to this thread...

Matt
Reply With Quote
  #5 (permalink)  
Old 11-22-2010, 07:07 AM
Trained Alumni
 
Posts: 343
Default

Possible solution is to install the Cross Root CA from Geotrust...we haven't tried it yet to know for sure.

Issue 10807 - android - Root Certificates missing from Android root store - Project Hosting on Google Code

https://knowledge.geotrust.com/suppo...=1283360269668

Matt
Reply With Quote
  #6 (permalink)  
Old 11-22-2010, 07:08 AM
Trained Alumni
 
Posts: 343
Default

Quote:
Originally Posted by sae65 View Post
Does this also apply to the 1024 bit certs?
No....but I don't know if you can get 1024 bit certs from Geotrust anymore.

Matt
Reply With Quote
  #7 (permalink)  
Old 11-22-2010, 07:10 AM
Active Member
 
Posts: 46
Default

Does this also apply to the 1024 bit certs?
Reply With Quote
  #8 (permalink)  
Old 11-22-2010, 08:23 AM
Intermediate Member
 
Posts: 16
Default

Just wondering if you guys that are having this problem with andriod phones are also have a problem with ZD? ZD now gives me a warning about untrusted certificate but the server and web browsers see no problems. I started a thread under the Zimbra Desktop area. ZD untrusted Verisign SSL cert

I also want to mention that my old cert was a 2048 bit key but I only needed one intermediate cert. Android phones and ZD worked perfectly then. Now I have to have two intermediate certs for things to be happy on the server and in web browsers.
Reply With Quote
  #9 (permalink)  
Old 11-22-2010, 09:12 AM
Active Member
 
Posts: 46
Default

JaymeH on this thread mentioned that his ZD were no longer working with the new cert.
Reply With Quote
  #10 (permalink)  
Old 11-25-2010, 08:49 AM
Trained Alumni
 
Posts: 343
Default

Quote:
Originally Posted by Chewie71 View Post
Possible solution is to install the Cross Root CA from Geotrust...we haven't tried it yet to know for sure.

Issue 10807 - android - Root Certificates missing from Android root store - Project Hosting on Google Code

https://knowledge.geotrust.com/suppo...=1283360269668

Matt
Anyone know where this CrossRoot cert should go? I tried putting it at the top of the commercial_ca.crt file, tried putting it at the bottom of the commercial.crt file....neither of those worked. Tried putting it at the top of the commercial.crt file and then the cert wouldn't even validate so I didn't try to deploy it.

Should this CrossRoot cert replace the normal root cert in the file....or just slip in next to it? Does the order of the certs in the file matter?

Matt
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.