Hi,
I've just renew a certificate on Thawte website using old CSR. I get my new certificate and when I'm trying to install it (web gui or cli) I'm getting errors :
with web gui :
Quote:
Mail : invalid request: missing required attribute: server Code d'erreur : service.INVALID_REQUEST Method: GetCertRequest Détails :soap:Sender
Error : : system failure: IOException while handling uploaded certificate
|
with cli :
Quote:
# /opt/zimbra/bin/zmcertmgr deploycrt comm /opt/certificates/2012_certificate.crt /opt/certs/thawte_Primary_Root_CA.pem
** Verifying /opt/certificates/2012_certificate.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/opt/certificates/2012_certificate.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
XXXXX ERROR: Invalid Certificate: /opt/certificates/2012_certificate.crt: /O=mail.ideus-consulting.com/OU=Go to https://www.thawte.com/repository/index.html/OU=Thawte SSL123 certificate/OU=Domain Validated/CN=mail.ideus-consulting.com
error 20 at 0 depth lookup:unable to get local issuer certificate
XXXXX ERROR: provided cert isn't valid.
|
I searched on the web for similar errors (and solutions) and found these pages, which did not help me that much
[SOLVED] thawte certificate renewal Unable to get issuer certificate - Zimbra :: Wiki
I used certificate decoder from
Certificate Decoder - Decode certificates to view their contents to test mine. Everything seems correct.
My actual certificate is not yet expired. I'll continue to search and if I find a solution I'll come back to post it, but if someone already find a solution I would be very grateful to him to share it.
regards
--
Jérôme
ZCS NE 6.0.14 for customers
ZCS OSE 7.1.3 for personal use