Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 09-18-2008, 05:22 AM
Senior Member
 
Posts: 55
Question Howto create certificate for server with multiple names

Hi All,

My server has two names:
1- mailhost.mydomain.br (for general purpouse)
2- webmail.mydomain.br (for web clients)

What is the best praticies to generate the csr certificate in this case? I am going to use CACert.
Should I use "common name" equal webmail.mydomain.br and "subjectAltNames" equal mailhost.mydomain.br or vice-versa?

If I use only one name in subjectAltNames my csr certificate there isn't SubjectAltName.
Look the command bellow.

[root@mailhost commercial]# /opt/zimbra/bin/zmcertmgr createcsr comm -new "/C=BR/ST=Rio de Janeiro/L=Rio de Janeiro/O=My Company/OU=My Depart/CN=webmail.mydomain.br" -subjectAltNames "mailhost.mydomain.br"
...
[root@mailhost commercial]# /opt/zimbra/bin/zmcertmgr viewcsr comm commercial.csr
subject=/C=BR/ST=Rio de Janeiro/L=Rio de Janeiro/O=My Company/OU=My Depart/CN=webmail.mydomain.br
SubjectAltName=
This also happen if I use the Administration Console.

But if I use more than one in SubjectAltName it works.

[root@mailhost commercial]# /opt/zimbra/bin/zmcertmgr createcsr comm -new "/C=BR/ST=Rio de Janeiro/L=Rio de Janeiro/O=My Company/OU=My Depart/CN=webmail.mydomain.br" -subjectAltNames "mailhost.mydomain.br,mail.mydomain.br"
...
[root@mailhost commercial]# /opt/zimbra/bin/zmcertmgr viewcsr comm commercial.csr
subject=/C=BR/ST=Rio de Janeiro/L=Rio de Janeiro/O=My Company/OU=My Depart/CN=webmail.mydomain.br
SubjectAltName= mailhost.mydomain.br, mail.mydomain.br

What should I do?

Best regards,
Bibo
Reply With Quote
  #2 (permalink)  
Old 09-18-2008, 11:53 PM
Intermediate Member
 
Posts: 15
Default

I also experience this issue when creating new certificates with alternate names. Why not file a bug?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.