Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 08-15-2011, 03:48 AM
Active Member
 
Posts: 41
Default ZCS: SSL certificates approaching expiration!

Hi,

in my inbox I have a mail from zimbra which says that the certificates willl expire soon.
To avoid this, the release notes for 7.1.2 say on page 10 to run these commands:

Code:
sudo zmcertmgr createca -new
sudo zmcertmgr deployca
sudo zmcertmgr deploycrt self -new
As this didn't work with the zimbra user I found this thread here in the forum:

Zimbra user password???

In this thread phoenix said that the commands could as well be run as root.
So I did this.

This is what I did:

Code:
root@mail:~#
root@mail:~# /opt/zimbra/bin/zmcertmgr createca -new
** Creating /opt/zimbra/ssl/zimbra/ca/zmssl.cnf...done
** Creating CA private key /opt/zimbra/ssl/zimbra/ca/ca.key...done.
** Creating CA cert /opt/zimbra/ssl/zimbra/ca/ca.pem...done.
root@mail:~#
root@mail:~#
root@mail:~#
root@mail:~# /opt/zimbra/bin/zmcertmgr deployca
** Importing CA /opt/zimbra/ssl/zimbra/ca/ca.pem into CACERTS...done.
** Saving global config key zimbraCertAuthorityCertSelfSigned...done.
** Saving global config key zimbraCertAuthorityKeySelfSigned...done.
** Copying CA to /opt/zimbra/conf/ca...done.
root@mail:~#
root@mail:~#
root@mail:~#
root@mail:~#
root@mail:~# /opt/zimbra/bin/zmcertmgr deploycrt self -new
Can't deploy cert for -new.  Unknown service.
root@mail:~#
root@mail:~#
root@mail:~#
root@mail:~#
root@mail:~#
root@mail:~# /opt/zimbra/bin/zmcertmgr deploycrt self
** Saving server config key zimbraSSLCertificate...done.
** Saving server config key zimbraSSLPrivateKey...done.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to /opt/zimbra/conf/ca...done.
root@mail:~#
root@mail:~#
root@mail:~#
root@mail:~#
Is that okay?
Zimbra is still running, but I'm afraid of the new restart... :-)

Michael
Reply With Quote
  #2 (permalink)  
Old 08-15-2011, 04:03 AM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

Quote:
Originally Posted by mludwig View Post
As this didn't work with the zimbra user I found this thread here in the forum:

Zimbra user password???

In this thread phoenix said that the commands could as well be run as root.
You're actually mis-quoting me. For clarification, my comment in that thread was in relation to becoming the Zimbra user not about generating the certificates.

Quote:
Originally Posted by mludwig View Post
Is that okay?
Zimbra is still running, but I'm afraid of the new restart... :-)
There should be no problems, for future reference the details of generating the Certificates are here: Administration Console and CLI Certificate Tools - Zimbra :: Wiki
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 08-15-2011, 07:38 AM
Active Member
 
Posts: 41
Default

Hi phoenix, sorry for misquoting you. :-)
Thank you again for your help and the link to the wiki. :-)
Reply With Quote
  #4 (permalink)  
Old 08-15-2011, 08:15 AM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

Quote:
Originally Posted by mludwig View Post
Hi phoenix, sorry for misquoting you. :-)
That's OK, the clarification was just for anyone else reading this thread.

Quote:
Originally Posted by mludwig View Post
Thank you again for your help and the link to the wiki. :-)
You're welcome.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 08-15-2011, 10:55 PM
Active Member
 
Posts: 41
Default

Good morning,

it's me again.

Quote:
Originally Posted by phoenix View Post
There should be no problems, [...]
After the daily restart there were still the old certificates installed in zimbra which were valid till 09/29/2011.


Quote:
Originally Posted by phoenix View Post
for future reference the details of generating the Certificates are here: Administration Console and CLI Certificate Tools - Zimbra :: Wiki
Taking the new Wiki article as a source of information everything worked fine. Now (after a restart of the system) I have the newly generated certificates running, valid till 2012.
So that's it, I'm running fine with the new certs now.

Michael
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.