Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-09-2011, 07:05 AM
Loyal Member
 
Posts: 95
Question [SOLVED] Unable to find renewed SelfSigned Certifiacte in Zimbra 7.1 after Renewal.

zmcontrol -v
Release 7.1.0_GA_3140.RHEL5_64_20110329150833 CentOS5_64 FOSS edition.

After renewing SelfSigned certificate ( tried both from Admin panel and from CLI) i just copied ca.pem ( tried both from /opt/zimbra/ssl/zimbra/ca & /opt/zimbra/conf/ca ) as a ca.pem.crt and install it on my desktop ( tried both XP & win7) but still i am getting Certificate warning ( in both outlook express and microsoft outlook)..

So what is the correct path of Self Signed certificate after renewal and before renewal ? is it
/opt/zimbra/ssl/zimbra/ca or /opt/zimbra/conf/ca or another?

can i renew my self signed certificate for more then 365 days? using bellow cli
zmcertmgr createcrt -new -days 786

i tried following from CLI
zmcertmgr createca -new
zmcertmgr createcrt -new -days 365
zmcertmgr deploycrt self
zmcertmgr deployca
zmcertmgr viewdeployedcrt

then zmcontroll stop; zmcontrol start
what is missing?

Last edited by sadiq007; 06-09-2011 at 07:07 AM.. Reason: add cli also
Reply With Quote
  #2 (permalink)  
Old 06-10-2011, 12:56 AM
Loyal Member
 
Posts: 95
Default

no reply yet from any expert?
Reply With Quote
  #3 (permalink)  
Old 06-11-2011, 04:57 AM
Active Member
 
Posts: 31
Default

Hi,

Try this [SOLVED] Zimbra Certificates have expired and I'm having difficulty regenerating them
Reply With Quote
  #4 (permalink)  
Old 06-14-2011, 03:33 AM
Loyal Member
 
Posts: 95
Default

Well i found the solution .. cert path is correct...it is /opt/zimbra/ssl/zimbra/ca/ca.pem but i was trying it for my secondary domain, and just come to know that it is working fine for primary domain, but not work for secondary domain...so i again renew my ssl cert from admin GUI...by selecting Install Certificate option (and replacing existing CSR) and must select..
Subject Alternative Name:mail.domain1.com and mail.domain2.com (add all your virtual domain).. and now certificate working fine for both domains.
Hope this will help lots of zimbra users..

but still some question are there... i renewed it for 786 days...but if i install it into my any pc after copying from /opt/zimbra/ssl/zimbra/ca/ as ca.pem.crt it is still showing me 365 days range.
and another question is it is working fine for all outllok express, ms outlook 2003, ms outlook 2010 but not working with ms outlook 2007.... hope some one have answers.

Last edited by sadiq007; 06-14-2011 at 03:36 AM.. Reason: explain in details
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.