Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-26-2009, 01:57 PM
Junior Member
 
Posts: 9
Default Error saving config key zimbraSSLCertificate

zcs 5.0.14 on ubuntu 8.04 with thawte certificate: can someone tell me what is attempting to happen during zmcertmgr deploycrt that gives this message:

** Saving server config key zimbraSSLCertificate...failed.
** Saving server config key zimbraSSLPrivateKey...failed.

i'm working with rogle and we've been fighting the whole commercial ssl/tls issues for a couple days. none of the solutions we've found on here seems to work. most of the steps say all is ok, then we restart everything and we get the:
network_biopair_interop: error writing 2108 bytes to the networ
k: Broken pipe

error. we've tried 15914 and 19702 and many other deriviatives there of! help!
Reply With Quote
  #2 (permalink)  
Old 03-26-2009, 02:06 PM
Zimbra Employee
 
Posts: 55
Default

Is the ldap service running?
Reply With Quote
  #3 (permalink)  
Old 03-26-2009, 02:17 PM
Junior Member
 
Posts: 9
Default

Quote:
Originally Posted by Ramadan Mansoura View Post
Is the ldap service running?
not at the moment. i figured i'd try deploying with zimbra stopped - should it be?
Reply With Quote
  #4 (permalink)  
Old 03-26-2009, 02:30 PM
Zimbra Employee
 
Posts: 55
Default

ldap needs to be running as the cert needs to be saved in ldap.
that's why you are seeing the error.
Reply With Quote
  #5 (permalink)  
Old 03-26-2009, 03:25 PM
Junior Member
 
Posts: 9
Default

zimbra@pfmail:~$ zmcontrol start
Host pfmail.memphis.css.local
Starting ldap...Done.
FAILED
Failed to start slapd. Attempting debug start to determine error.
TLS: error:0906D06C:PEM routines:PEM_read_bio:no start line pem_lib.c:647
TLS: error:0906D06C:PEM routines:PEM_read_bio:no start line pem_lib.c:647
TLS: error:02001002:system library:fopen:No such file or directory bss_file.c:356
TLS: error:20074002:BIO routines:FILE_CTRL:system lib bss_file.c:358
main: TLS init def ctx failed: -1

great - now ldap wont start! is it obvious from this whats broke now?
Reply With Quote
  #6 (permalink)  
Old 03-26-2009, 03:37 PM
Zimbra Employee
 
Posts: 55
Default

1) check the permissions on those two files:
-rw-r--r-- 1 zimbra zimbra 1001 Mar 13 19:40 /opt/zimbra/conf/slapd.crt
-rw-r--r-- 1 zimbra zimbra 887 Sep 21 2008 /opt/zimbra/conf/slapd.key

2) is your private key encrypted or password protected?
Reply With Quote
  #7 (permalink)  
Old 03-26-2009, 06:35 PM
Junior Member
 
Posts: 9
Default

zimbra@pfmail:~/conf$ ls -l slapd*
-rw-r----- 1 zimbra zimbra 7562 Mar 26 17:22 slapd.conf
-rw-r----- 1 zimbra zimbra 7575 Mar 26 13:51 slapd.conf.in
-rw-r--r-- 1 zimbra zimbra 10827 Mar 26 15:39 slapd.crt
-rw-r--r-- 1 zimbra zimbra 920 Mar 26 15:39 slapd.key

perms look ok. my partner built the key this time, but i've not been prompted for one with all the verifying/deploying - i think that would've come up by now!
any other suggestions?

btw - thanks for your efforts in this! we may build from scratch tomorrow...
Reply With Quote
  #8 (permalink)  
Old 03-26-2009, 09:14 PM
Zimbra Employee
 
Posts: 55
Default

So ldap service is running now? What happens if you deploy the cert at this point?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.