Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 11-09-2006, 03:45 AM
Starter Member
 
Posts: 1
Default Seperate SSL Certs for pop/imap/smtp/web

I'm in an environment where whilst we currently only have one Zimbra box, but we will be expanding to a multi-server setup before long. As such, we have set up DNS so that pop.zimbra.ourdomain.com, smtp.zimbra.ourdomain.com, etc all point to the same place. The plan is that at some point, these will be on different boxes with different IPs, and so we're allowing for the future expansion.

My question is, how can I install SSL certificates so that the certs match the appropriate hostnames? The Wiki and the forum post linked below were very informative, but I can only see how to give a separate cert to the smtpd, (by having hand-placed /opt/zimbra/conf/smtpd.crt and /opt/zimbra/conf/smtpd.key) but I can't see how to do separate certs for imap, pop and web access.

Any pointers would be wonderful, and if the answer has to be 'Nope, can't do that' then do people think I should bung it in as a feature request?

----
Handy forum post: [SOLVED] Installing existing SSL certificates (solved)
Reply With Quote
  #2 (permalink)  
Old 11-14-2006, 07:28 AM
Trained Alumni
 
Posts: 193
Default Wildcard Cert

I don't know if it's an option for you, but you could try using a wildcard cert. I've been testing it myself and have been pretty successful with SMTP/TLS(port 25), https, imap(on perdition), and pop(on perdition) using a test cert from thawte. I haven't gotten smtp over ssl(port 465) working yet, but am working with support on it.

The wildcard cert would allow you to use any DNS name you want. If you need to change it in the future, you don't have to get a new cert. However, it also costs a little extra $$.
Reply With Quote
  #3 (permalink)  
Old 10-27-2007, 05:03 PM
New Member
 
Posts: 3
Default Any update on this?

I would also like to use separate DNS names for each service to make them easier to manage. Has anyone gotten this to work without using a wildcard certificate?

Thanks,
Philip
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.