Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-26-2011, 08:12 PM
Intermediate Member
 
Posts: 19
Default [SOLVED] unable to load certificate - when creating new self signed cert

After moving to a new Server (Ubuntu 6.06 32 -> 10.04 64), the logger service is not working correctly. In the Admin GUI Server status shows:
Quote:
Server status data is not available. To see the server status, loggers service must be installed.
Running zmcontrol -status shows everything is working correctly. The mail server has been functioning without any problems, except for the stats and status not working.

I suspected this may have something to do with the self signed cert we had to create during the move(in hindsight I think it might have complained of something in the process). So I decided to recreate the cert, and noticed that I am getting two errors.

On step 3 from Administration Console and CLI Certificate Tools - Zimbra :: Wiki, I get the following:

Code:
root@u10-04-zimbra:/opt/zimbra/bin# ./zmcertmgr deploycrt self
** Saving server config key zimbraSSLCertificate...done.
** Saving server config key zimbraSSLPrivateKey...done.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to /opt/zimbra/conf/ca...unable to load certificate
26819:error:0906D06C:PEM routines:PEM_read_bio:no start line:pem_lib.c:650:Expecting: TRUSTED CERTIFICATE
done.
And on step 4:
Code:
root@u10-04-zimbra:/opt/zimbra/bin# ./zmcertmgr deployca
** Importing CA /opt/zimbra/ssl/zimbra/ca/ca.pem into CACERTS...done.
** Saving global config key zimbraCertAuthorityCertSelfSigned...done.
** Saving global config key zimbraCertAuthorityKeySelfSigned...done.
** Copying CA to /opt/zimbra/conf/ca...done.
unable to load certificate
27225:error:0906D06C:PEM routines:PEM_read_bio:no start line:pem_lib.c:650:Expecting: TRUSTED CERTIFICATE
I have moved mailboxd/etc/keystore out of the way and tried this, with the same results.

So far I have been unable to locate an existing solution in the forums.
__________________
Release 7.0.1_GA_3105.UBUNTU10_64 UBUNTU10_64 FOSS edition
Release 7.0.1_GA_3105.UBUNTU8 UBUNTU8 FOSS edition
Reply With Quote
  #2 (permalink)  
Old 02-08-2011, 02:51 PM
Junior Member
 
Posts: 8
Default

Well, I have got the same error. After i did ./install.sh -u and lost all my emails.... I found out, that its not an zimbra issue, but an open-ssh issue.
I have reinstalled ssh and openssh-server and the problem was solved.

I think, the error was caused by the validity of the ssh certificate.
Reply With Quote
  #3 (permalink)  
Old 02-15-2011, 07:07 PM
Intermediate Member
 
Posts: 19
Default

I finally had a chance to try your solution tonight, but no success so far.

Did you just remove and the install openssh-server and ssh, or did you completely purge them. Did you have to re-install zimbra or do the certs again after?
__________________
Release 7.0.1_GA_3105.UBUNTU10_64 UBUNTU10_64 FOSS edition
Release 7.0.1_GA_3105.UBUNTU8 UBUNTU8 FOSS edition
Reply With Quote
  #4 (permalink)  
Old 02-20-2011, 10:35 AM
Junior Member
 
Posts: 8
Default

Quote:
Originally Posted by mbert View Post
I finally had a chance to try your solution tonight, but no success so far.

Did you just remove and the install openssh-server and ssh, or did you completely purge them. Did you have to re-install zimbra or do the certs again after?
I did reinstall Zimbra as well.
Reply With Quote
  #5 (permalink)  
Old 03-04-2011, 12:55 PM
Intermediate Member
 
Posts: 19
Default

Well, after having no luck. I migrated everything over to a new server running 10.04.2 LTS, ZCS 6.0.10. Still wasn't working, so I re-installed openssh-server and then upgraded to ZCS 7.0.0 and voila, certs are working again.

But I am still having a problem that the server status is data is not available, so it must not be related to the ssl certs. I'll post a new thread for that one.
__________________
Release 7.0.1_GA_3105.UBUNTU10_64 UBUNTU10_64 FOSS edition
Release 7.0.1_GA_3105.UBUNTU8 UBUNTU8 FOSS edition
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.