Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-01-2012, 02:27 PM
Junior Member
 
Posts: 7
Unhappy Trying to install Globalsign SSL certificate

I'm trying to install a commercial certificate for hours now, but I just cannot get it to work (on Zimbra Server 7.1 OS version).

A week ago I have ordered a GlobalSign Domain validated certificate. I successfully installed the certificate on my webserver. However now I'm trying to install it on Zimbra Server, but as stated without luck.

I tried to install the certificate using the admin interface:

- First I created the CSR
- Next I choose the three .cer files provided by GlobalSign
- After clicking 'Finish' I get the following error:

Quote:
system failure: XXXXX Error: Unmatching certificate (/opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current.crt) and private key (/opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current_comm.key) pair.
I also tried another approach (using the commandline) without any luck:

Code:
./zmcertmgr deploycrt comm /ssl/www_domain_com.key /ssl/ca_bundle.crt
But that resulted in a similar error:

Quote:
** Verifying /ssl/www_domain_com.key against /opt/zimbra/ssl/zimbra/commercial/commercial.key
unable to load certificate
140117204260496:error:0906D06C:PEM routines:PEM_read_bio:no start lineem_lib.c:696:Expecting: TRUSTED CERTIFICATE
XXXXX ERROR: Unmatching certificate (/ssl/www_domain_com.key) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) pair.
XXXXX ERROR: provided cert isn't valid.
I don't have any more ideas as to how to get it working .

P.S. If it matters I still have the 'original' CSR en .key file which I used to request the certificate at GlobalSign.

Any help is much appreciated.
Reply With Quote
  #2 (permalink)  
Old 02-11-2012, 10:41 AM
Junior Member
 
Posts: 7
Default

Nobody is able to help me with this issue?
Reply With Quote
  #3 (permalink)  
Old 02-14-2012, 08:01 PM
Starter Member
 
Posts: 1
Default

I'm not sure if this will help - but I was having a *very* similar problem and this page helped a lot:

Zimbra | dave-smith.co.uk

The verifycert command failed and when I opened my commercial.crt file, it had a line with both -----end----------begin----- on the same line!

I added a newline in the correct place and the verifycrt worked fine. I then deployed the cert and restarted mailboxd.

After that - it worked great! Hope it helps!
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.