Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-07-2008, 01:04 PM
Intermediate Member
 
Posts: 17
Angry Cannon install commercial ssl cert after upgrade via admin web gui.

I upgraded to 5 today and was very happy to see a gui for installing ssl certs.

I already have a wild card cert from digicert so I went to the wizard.

No problems until the very end after selecting finish i get the following.

Your certificate was not installed due to the error : system failure: XXXXX ERROR: failed to create jetty.pkcs12 Message: Your certificate was not installed due to the error : system failure: XXXXX ERROR: failed to create jetty.pkcs12 Error code: ZaCertWizard.prototype.installCallback Method: AjxException.UNKNOWN_ERROR Details:system failure: XXXXX ERROR: failed to create jetty.pkcs12
Reply With Quote
  #2 (permalink)  
Old 01-07-2008, 01:06 PM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Default

Out of curiosity, are you not in the US?
Reply With Quote
  #3 (permalink)  
Old 01-07-2008, 01:18 PM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Default

We suggest waiting until 5.0.1 is out for Commercial Cert use/installation. There are several fixes for Commercial Certs that you'll need.
Reply With Quote
  #4 (permalink)  
Old 01-07-2008, 01:24 PM
Intermediate Member
 
Posts: 17
Default

Quote:
Originally Posted by jholder View Post
Out of curiosity, are you not in the US?
Out of curiosity, why do you ask?

Anyway I am in the US.
Reply With Quote
  #5 (permalink)  
Old 01-07-2008, 01:25 PM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Default

Quote:
Originally Posted by webaj View Post
Out of curiosity, why do you ask?

Anyway I am in the US.
There was a separate issue I thought you might be hitting. Turns out that's not it.
Reply With Quote
  #6 (permalink)  
Old 01-11-2008, 09:58 AM
Intermediate Member
 
Posts: 17
Default

Quote:
Originally Posted by jholder View Post
We suggest waiting until 5.0.1 is out for Commercial Cert use/installation. There are several fixes for Commercial Certs that you'll need.

I upgraded the server today and still get the following problem.

Your certificate was not installed due to the error : system failure: XXXXX ERROR: failed to create jetty.pkcs12 Message: Your certificate was not installed due to the error : system failure: XXXXX ERROR: failed to create jetty.pkcs12 Error code: ZaCertWizard.prototype.installCallback Method: AjxException.UNKNOWN_ERROR Details:system failure: XXXXX ERROR: failed to create jetty.pkcs12
Reply With Quote
  #7 (permalink)  
Old 01-11-2008, 04:22 PM
Zimbra Employee
 
Posts: 538
Default

Try installing with the command line interface and post the full error message. As zimbra

Code:
sudo zmcertmgr deploycrt comm  
If your cert authority has a root ca plus intermediaries you'll need to concatenate them into one file.
__________________
Bugzilla - Wiki - Downloads - Before posting... Search!
Reply With Quote
  #8 (permalink)  
Old 01-14-2008, 07:41 AM
Intermediate Member
 
Posts: 17
Default

Quote:
Originally Posted by brian View Post
Try installing with the command line interface and post the full error message. As zimbra

Code:
sudo zmcertmgr deploycrt comm  
If your cert authority has a root ca plus intermediaries you'll need to concatenate them into one file.

zimbra@abby:/opt/key> sudo zmcertmgr deploycrt comm /opt/key/star_example_org.crt /opt/key/DigiCertCA.crt
** Verifying /opt/key/star_example_org.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
XXXXX ERROR: Unmatching certificate (/opt/key/star_example_org.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) pair.
XXXXX ERROR: provided cert isn't valid.

or


zimbra@abby:/opt/key> sudo zmcertmgr deploycrt comm
** Verifying /opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: /opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current.crt: OK
** Copying /opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Appending ca chain /opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current_chain.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Installing Certificates from /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20080114092253
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...failed.

XXXXX ERROR: failed to create jetty.pkcs12
No certificate matches private key
Reply With Quote
  #9 (permalink)  
Old 01-14-2008, 09:47 AM
New Member
 
Posts: 3
Default

This is my first post so hope I am doing things correctly.

Anyway, fwiw I am having the same problem when installing commercial certificates. I tried using the web interface and using the command line with the same results as the last poster.

It errors the same way via the web interface when I try to create a self-signed certificate while renaming the Location, Organization, Department, etc.

After receiving the error with the self-signed certificate and not reinstalling the original certificate the web interface will disappear after a system restart. This does not happen after the error if I try to install a commercial certificate.
Reply With Quote
  #10 (permalink)  
Old 01-14-2008, 05:01 PM
Zimbra Employee
 
Posts: 538
Default

Jonl:

The current openssl policy doesn't support changing the Locale, City, ST when generating a self-signed cert. This has been fixed for 5.0.2.

webaj:

This means the cert you are trying to install doesn't match the private key? Did you generate the csr from the zimbra wizard? If not you'll need to install the private key from where ever you generated the csr to send to your commercial cert provider.
__________________
Bugzilla - Wiki - Downloads - Before posting... Search!
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com




 

Search Engine Optimization by vBSEO 3.1.0