Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-18-2008, 01:33 PM
Senior Member
 
Posts: 50
Default [SOLVED] Godaddy SSL certificate installation

Anybody knows how to install godaddy SSL certificate on Zimbra network edition Professional 5.06GA? The doucment on Zimbra Wiki is not clear. I tried several times, but failed. Please help!!!
Reply With Quote
  #2 (permalink)  
Old 06-18-2008, 01:53 PM
Moderator
 
Posts: 6,236
Default

Are you following this article? Commercial Certificate in 5.x - Zimbra :: Wiki

Other's hit this issue on 5.0.6:
Bug 28085 – zmcertmgr doesn't break down the concatenated commercial cert from Ldap
http://www.zimbra.com/forums/adminis...html#post95454

Admin console:
A) The easiest workaround is to specify "--- All Servers ---" as the target server when installing the commericial cert from the admin console.

CLI:
B) The other way is to create the commercial_ca.crt (concantenated chain file) manually under /opt/zimbra/ssl/zimbra/commercial.
Order of the GoDaddy chain certs for concatenation:
* RootCA
* gd_cross_intermediate.crt
* gd_intermediate.crt
* server_name.crt
Then use the zmcertmgr command.

Last edited by mmorse; 06-18-2008 at 02:07 PM.. Reason: he did say 5.0.6
Reply With Quote
  #3 (permalink)  
Old 06-18-2008, 02:22 PM
Senior Member
 
Posts: 50
Default

Thanks mmorse! let me make my situation more clear.
We bought SSL certificate from Goddy since we get warning message of "There is a problem with this website's security certificate". Then we generated CSR file in Admin console and sent to Godaddy. We get server_name.crt file from Godaddy and we also download RootCA, gd_cross_intermediate.crt and gd_intermediate.crt file from their website. We tried install those certificate files from Admin console, but always get error message of "Your certificate was not installed due to the error: system failure:XXXXX ERROR: Invalid Certificate:"

Thanks in advance!
Reply With Quote
  #4 (permalink)  
Old 06-18-2008, 02:28 PM
Moderator
 
Posts: 1,027
Default

I had the same problem till I loaded the cert for "All Servers." Take a look at this post:
http://www.zimbra.com/forums/adminis...html#post95868
__________________
Cheers,

Dan
Reply With Quote
  #5 (permalink)  
Old 06-28-2008, 06:32 PM
Senior Member
 
Posts: 50
Default Thanks a lot!

Thanks everybody for your very useful info.
Reply With Quote
  #6 (permalink)  
Old 07-16-2008, 04:26 PM
Intermediate Member
 
Posts: 21
Default

So I followed the instructions in the above threads and installed my GoDaddy cert. Now I am unable to connect through an SSL connection. Is there anything I can do to reinstall the self signed cert and start from scratch?
Reply With Quote
  #7 (permalink)  
Old 07-16-2008, 04:53 PM
Moderator
 
Posts: 1,027
Default

Quote:
Originally Posted by natediggs View Post
So I followed the instructions in the above threads and installed my GoDaddy cert. Now I am unable to connect through an SSL connection. Is there anything I can do to reinstall the self signed cert and start from scratch?
If it really installed, you might try connecting from another browser/machine and see if the problem is server side or client side. If another machine connects, you may have to delete the old self-signed cert & path from your browser because it sees the new cert and thinks something is rotten. . .
__________________
Cheers,

Dan
Reply With Quote
  #8 (permalink)  
Old 07-16-2008, 05:19 PM
Intermediate Member
 
Posts: 21
Default

I actually just decided to start from scratch and recreate a new keystore. Now I've generated the CSR and created a GoDaddy cert from it and I get this error:
Your certificate was not installed due to the error : system failure: XXXXX ERROR: Unmatching certificate (/opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current.crt) and private key (/opt/zimbra/mailboxd/webapps/zimbraAdmin/tmp/current_comm.key) pair.

So it seems I have a mismatched key pair. Any idea how I can reinstall it?
Reply With Quote
  #9 (permalink)  
Old 07-17-2008, 10:28 AM
Moderator
 
Posts: 1,027
Default

I'm just guessing here, but a guess is better than nothing, I hope (?).

How, exactly, did you generate the new keystore? Did you stop & restart Zimbra services after doing so? I'm wondering if perhaps the CSR was generated on the old key because of not restarting Zimbra?
__________________
Cheers,

Dan
Reply With Quote
  #10 (permalink)  
Old 07-17-2008, 10:48 AM
Intermediate Member
 
Posts: 21
Default

I recreated the keystore using steps I found on the Wiki and have restarted the server several times.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.