Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-15-2006, 08:29 AM
Active Member
 
Posts: 46
Thumbs up Commercial SSL Cert

I followed the instructions at http://wiki.zimbra.com/index.php?tit...l_Certificates

When I reach step 2B (import cert into the commercial keystore) I get the following error:

keytool error: java.lang.Exception: Failed to establish chain from reply

Any ideas?
__________________
Sincerely,

Alex

Last edited by alexz; 04-23-2006 at 08:56 AM..
Reply With Quote
  #2 (permalink)  
Old 04-15-2006, 09:12 AM
Zimbra Consultant & Moderator
 
Posts: 19,633
Default

Installation of a Commercial Certificate is outside the scope of these forums but have you tried the Certificate vendor's site? Here's what Thawte have to say on the error and, of course, google will give you plenty to read.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 04-15-2006, 09:34 AM
Active Member
 
Posts: 46
Default

Bill,

I don't think that's a realistic answer. The digital cert is for use on a Zimbra server. Why would that not be related to the forums? I have searched those same web sites but they are generic and don't take into account Zimbra's software. In particular, I don't want to dig myself into a hole by just hacking away at proposed solutions without knowing how or if they will affect ZCS.

I was hoping to find someone else who had this problem or perhaps see if someone at Zimbra knows what is causing it. I purchased the certificate from GoDaddy.com.
__________________
Sincerely,

Alex

Last edited by alexz; 04-15-2006 at 09:39 AM..
Reply With Quote
  #4 (permalink)  
Old 04-15-2006, 10:14 AM
Former Zimbran
 
Posts: 5,606
Default

alexz,
I think perhaps we could give it a shot.
Are you doing this as root or as zimbra user?

Also, could you post your /var/log/zimbra.log and /opt/zimbra/log/zimbra.log? Perhaps there's a little more in there.
Reply With Quote
  #5 (permalink)  
Old 04-15-2006, 10:20 AM
Zimbra Consultant & Moderator
 
Posts: 19,633
Default

Well, the requirements of each supllier are vary - that's why I pointed you to google.

What have you done to find out what the problem might be? What does the GoDaddy site say about this error? Did you also search the forums to see if this has been covered before? Is the certificate you've got in the correct format? Did you read any of the google links? They're quite specific about this error.
__________________
Regards


Bill
Reply With Quote
  #6 (permalink)  
Old 04-15-2006, 10:46 AM
Active Member
 
Posts: 46
Default

Bill,

Not to be rude but the reason I posted this message in the first place is to find a solution to a problem that I am having with installing a digital certificate purchased from a commercial provider. I have generated a request using the commands specified in the Wiki post and used that request to obtain a commercial certificate from a CA, GoDaddy. I paid for a certificate and they sent me one. How I use that certificate is not their concern. I have used their certificates on Windows IIS servers for years and never had any problems. Clearly, installing certificates is very different in this situation which is why I am asking for help. I'm certainly not going to call GoDaddy and ask them how to install their certificate on a Zimbra server.
__________________
Sincerely,

Alex
Reply With Quote
  #7 (permalink)  
Old 04-15-2006, 11:09 AM
Zimbra Employee
 
Posts: 515
Default

it should be like installing into any other tomcat. godaddy has pretty lame help/faq section but there is an "Installing Your SSL Certificate" page which has a link to "Installing SSL Certificate - Tomcat 4.x/5.x"

also, i copied the error into google, clicked "i'm feeling lucky" and i got this page: http://www.thawte.com/ssl-digital-ce...va.html#error3

both of which lead me to follow up phoenix: a.) what format is the cert? and b.) did you install the root and intermediate certs first?
__________________
Search the Forums - Bugzilla - Wiki - Downloads
Reply With Quote
  #8 (permalink)  
Old 04-15-2006, 11:17 AM
Active Member
 
Posts: 46
Default

Quote:
Originally Posted by wannabetenor
alexz,
I think perhaps we could give it a shot.
Are you doing this as root or as zimbra user?

Also, could you post your /var/log/zimbra.log and /opt/zimbra/log/zimbra.log? Perhaps there's a little more in there.
Thanks! They keytool didn't work while logged in as root. I used it as su zimbra.

Here are the files. Nothing out of the ordinary. I ran the command in 2b and then took a snapshot of the logs.
Attached Files
File Type: txt OptZimbraLog.txt (26.7 KB, 237 views)
File Type: txt VarLogZimbra.txt (3.9 KB, 214 views)
__________________
Sincerely,

Alex
Reply With Quote
  #9 (permalink)  
Old 04-15-2006, 11:41 AM
Zimbra Consultant & Moderator
 
Posts: 19,633
Default

Quote:
Originally Posted by alexz
Bill,

Not to be rude but the reason I posted this message in the first place is to find a solution to a problem that I am having with installing a digital certificate purchased from a commercial provider.
I don't take your reply as being rude, I just don't understand why you didn't bother following any of the links that I provided. They were specific to your question and covered the reason why you got that error message. The point about following the wiki instructions is not to get to a point where there's an error and say 'I 've got this error, how do I fix it?', surely the point is to do some investigation as to why you've got the error and try to fix it yourself. Well, you asked the question and I pointed you to possible solutions but you seem to want someone to lead you by the hand through the problem, that's not my style and I'm sorry if that seems to offend you.

If, after doing your own investigation, you're stumped then by all means ask a question and detail what you've done to get to that stage and people will be willing to help.
__________________
Regards


Bill
Reply With Quote
  #10 (permalink)  
Old 04-15-2006, 11:49 AM
Active Member
 
Posts: 46
Default

Quote:
Originally Posted by bobby
it should be like installing into any other tomcat. godaddy has pretty lame help/faq section but there is an "Installing Your SSL Certificate" page which has a link to "Installing SSL Certificate - Tomcat 4.x/5.x"

also, i copied the error into google, clicked "i'm feeling lucky" and i got this page: http://www.thawte.com/ssl-digital-ce...va.html#error3

both of which lead me to follow up phoenix: a.) what format is the cert? and b.) did you install the root and intermediate certs first?
Bobby - I did what that page said "Installing Your Issued Web Server Certificate" as well as importing the root and intermediate certificates. Where it says "Updating the server.xml configuration file" - I assume this is not necessary since the server.xml points to the correct Zimbra keystore?

As far as the format they send a .crt file, which is an x.509 certificate to the best of my understanding.
__________________
Sincerely,

Alex

Last edited by alexz; 04-15-2006 at 12:00 PM..
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.