I'm just guessing here, but a guess is better than nothing, I hope (?).
How, exactly, did you generate the new keystore? Did you stop & restart Zimbra services after doing so? I'm wondering if perhaps the CSR was generated on the old key because of not restarting Zimbra?
__________________
Cheers,
Dan
|