At this for days now and nearly have it.

My private key and commercial.crt match but there is something wrong with the commercial_ca.crt

I'm following this howto Installing a GeoTrust Commercial Certificate - Zimbra :: Wiki
and geotrust has its intermediate certs here https://knowledge.geotrust.com/suppo...tent&id=AR1423

which one should I use?

This is the error I get....

[root@mail commercial]$ /opt/zimbra/bin/zmcertmgr verifycrt comm commercial.key commercial.crt
** Verifying commercial.crt against commercial.key
Certificate (commercial.crt) and private key (commercial.key) match.
Error loading file /opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt
20200:error:0906D064:PEM routines:PEM_read_bio:bad base64 decodeem_lib.c:759:
20200:error:0B084009:x509 certificate routines:X509_load_cert_crl_file:PEM lib:by_file.c:280:
usage: verify [-verbose] [-CApath path] [-CAfile file] [-purpose purpose] [-crl_check] [-engine e] cert1 cert2 ...
recognized usages:
sslclient SSL client
sslserver SSL server
nssslserver Netscape SSL server
smimesign S/MIME signing
smimeencrypt S/MIME encryption
crlsign CRL signing
any Any Purpose
ocsphelper OCSP helper
XXXXX ERROR: Invalid Certificate:
[root@mail commercial]$

Any ideas?