I think problem is about using Pop3SSL between Zimbra Proxy and Zimbra Mailboxes.
Client is using Pop3 to connect to Zimbra Proxy, but SSL is still using...
Is there any way to disable SSL communication between Zimbra Proxy and Zimbra Mailbox?
172.22.28.40 -> user
172.30.14.10 -> zimbra proxy
172.30.14.13 -> zimbra mailbox
2013/03/06 09:18:47 [error] 5573#0: *177420 SSL_read() failed (SSL: error:1408F119:SSL routines:SSL3_GET_RECORD:decryption failed or bad record mac) while proxying and reading from upstream, client: 172.22.28.40, server: 0.0.0.0:110, login: "<userid>", upstream: 172.30.14.13:995 (172.22.28.40:1134-172.30.14.10:110) <=> (172.30.14.10:45745-172.30.14.13:995)
And AGD confirmed that the issue is present even on single server installation, with no proxy.
Refer to Bug 80563 I had raised.
I have encounter the same problem. Disabling SSL to upstream from web admin don't seem to be really disabled.
Disabling SSL to upstream with zmprov solved the problem.
zmprov ms $(zmhostname) zimbraReverseProxySSLToUpstreamEnabled FALSE
Is yours a single server or multiserver? ON what servers did you disable SSL to upstream? Mailbox servers? Proxy servers? or all servers?
I do this modification on a single server installation.
This command changes the nginx configuration so i think it should be done on proxy servers.