Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-20-2007, 06:13 AM
Special Member
 
Posts: 164
Question restoring SSL with Keytool???

Hi All

Having been playing with commercial certs for a few days and I wondered if anyone had found a way to restore certs using keytool from the .key and .crt files.

What is clear is the wiki way to install certs works fine for the basic tomcat stuff as you have a sequence of Create Store, Request Cert from a CA, Import Cert from CA (and any intermediates) and restart Zimbra services.

I used the java routine in the wiki to extract the .key file, and backed up the whole of Zimbra and the crt files. Then started playing with all sorts of SSL cert stuff till it eventually broke. Then I expected to be able to use the .key and the .crt files to recreate the keystore in a clean install of Zimbra, simulating a disaster recovery scenario, but I cant do it. Tried using zmcertinstall but although there is no error on the command line it shows up in the mailbox log as

javax.net.ssl.SSLException: No available certificate or key corresponds to the SSL cipher suites which are enabled.

and no https or other SSL is available.

So I am looking for a way of perhaps using the key file and keytool to somehow import it. Looking at all the FAQs and manuals around they seem to be geared to the create/request/import cycle not the aagghhhh server died now where are the crt and key files cycle ;-)

Tried daft stuff like creating a new csr and seeing if the crt will import against it but the key is obviously going to be different. Worth mentioning at each new attempt I am starting with a clean Zimbra install.

Anyone have any ideas? I have the original keystore and crts backup still if that helps.

Need to have some form of recovery for DR purposes or to know the risks at least, before it happens on a live system!

K
Reply With Quote
  #2 (permalink)  
Old 04-23-2007, 05:48 AM
Elite Member
 
Posts: 371
Default

not sure if this will help:
http://www.zimbra.com/forums/showthr...ed=1#post44415
p.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.