Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack (1) Thread Tools Display Modes
  #41 (permalink)  
Old 01-05-2008, 11:57 PM
Special Member
 
Posts: 100
Default

Any update on this TLS issue? .. Both our production server and test server have the same issue .. the fix was to set all YES to NO in the ldap cf files as stated in this last posting .. it seems this is something of a major bug .. how could all of the beta folks have not seen this and it get passed to GA ??

BRW
Reply With Quote
  #42 (permalink)  
Old 01-06-2008, 12:00 AM
Zimbra Consultant
 
Posts: 5,606
Default

Yeah, it caught us by surprise as well.

The fix for this and the commercial cert issue will be in 5.0.1 which is set to be released really really soon. Can't give an exact date, but soon
Reply With Quote
  #43 (permalink)  
Old 01-06-2008, 12:08 AM
Special Member
 
Posts: 100
Default

THanks for the update .. it sure freaked us out after the update appeared to go well but then ZERO email in/out ..

Hope to see 5.0.1 soon

BRW
Reply With Quote
  #44 (permalink)  
Old 01-07-2008, 05:09 PM
Active Member
 
Posts: 48
Default

Quote:
Originally Posted by brwatters View Post
THanks for the update .. it sure freaked us out after the update appeared to go well but then ZERO email in/out ..

Hope to see 5.0.1 soon

BRW
Yes, we experienced the same panic. The main bug that GA was going to address for us worked wonderfully.. and honestly.. I did not do much more testing until I saw a flurry of bounces from another of our mail servers.

Caveat constructum.
Reply With Quote
  #45 (permalink)  
Old 01-08-2008, 01:17 PM
Junior Member
 
Posts: 7
Default

We encountered this same problem and after reading through this thread, I applied the suggested steps (including the additional steps of disabling tls) and yet the error still occurred. We just figured out that it is related to shared calendars. If shared calendars are enabled, the same error about an expired certificate occurs, but if the shared calendars are unchecked, the error goes away. Does anyone have an idea of where this could be originating? And hopefully, the 5.0.1 fix will catch this aspect as well. Thanks.
Reply With Quote
  #46 (permalink)  
Old 01-09-2008, 03:47 PM
Junior Member
 
Posts: 7
Default

Just to follow up to my own post:

This problem was resolved by Zimbra Support. In addition to the certificate files, Sun java keeps certificates in a keystore file. Here is the solution as received from support:
The keystore showed still the old certificate entry for tomcat now that we have moved to jetty

keytool -list -keystore /opt/zimbra/mailboxd/etc/keystore -storepass `zmlocalconfig -s -m nokey mailboxd_keystore_password`

Keystore type: JKS
Keystore provider: SUN

Your keystore contains 2 entries

jetty, Jan 8, 2008 , PrivateKeyEntry,
Certificate fingerprint (MD5): xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx
tomcat, Jun 5, 2006 , PrivateKeyEntry,
Certificate fingerprint (MD5): xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx

Deleted tomcat alias with

keytool -delete -alias tomcat -keystore /opt/zimbra/mailboxd/etc/keystore -storepass `zmlocalconfig -s -m nokey mailboxd_keystore_password`

zmcontrol stop
zmcontrol start
Hopefully, this will help someone else with similar problems.

Wendell
Reply With Quote
  #47 (permalink)  
Old 01-10-2008, 05:40 AM
Member
 
Posts: 10
Default

Quote:
Originally Posted by gwjones View Post
Just to follow up to my own post:
Deleted tomcat alias with

keytool -delete -alias tomcat -keystore /opt/zimbra/mailboxd/etc/keystore -storepass `zmlocalconfig -s -m nokey mailboxd_keystore_password`

zmcontrol stop
zmcontrol start

Wendell
Thanx Wendell, this post saved my but bigtime today, since for some reasons we kept getting internal errors with shared calendars rendering our planning departments powerless to function.

John Tolenaars
Reply With Quote
  #48 (permalink)  
Old 01-10-2008, 06:58 PM
Moderator
 
Posts: 986
Default

Quote:
Originally Posted by gwjones View Post
... In addition to the certificate files, Sun java keeps certificates in a keystore file....
Hmm the output I receive from that command is the following:
Code:
Keystore type: JKS
Keystore provider: SUN

Your keystore contains 1 entry

tomcat, Feb 16, 2007, PrivateKeyEntry,
Certificate fingerprint (MD5): 19:44:7D:E8:A8:D8:19:90:39:42:E8:AF:D2:3E:AA:25
Is this a problem in any way? I seem to be missing the jetty keystore entirely.
Reply With Quote
  #49 (permalink)  
Old 01-13-2008, 06:29 AM
Active Member
 
Posts: 44
Default

I think I'm encountering the same problem with 5.0.1 NE. After a clean install I have requested a commercial certificate. I installed it trough the web interface without any problems.

But after this action the servers stops sending and receiving mail. The log file is flooded with messages like Unable to set STARTTLS.

What should I do? When I use the command as above I get back that there is 1 entry in my keystore, jetty. I hope someone can assist me.
Reply With Quote
  #50 (permalink)  
Old 01-13-2008, 08:35 AM
Active Member
 
Posts: 44
Default

Quote:
Originally Posted by bramm View Post
I think I'm encountering the same problem with 5.0.1 NE. After a clean install I have requested a commercial certificate. I installed it trough the web interface without any problems.

But after this action the servers stops sending and receiving mail. The log file is flooded with messages like Unable to set STARTTLS.

What should I do? When I use the command as above I get back that there is 1 entry in my keystore, jetty. I hope someone can assist me.
I have edited the ldap files not to load the tls as stated above. So everything works now, but this is not the right way to go I think. I assume that a commercial certificate should be installed correctly when using the web interface.

I'm using ubuntu and the corresponding version.
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com