Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #11 (permalink)  
Old 01-04-2010, 12:13 PM
Intermediate Member
 
Posts: 18
Default

Your suggesting some kind of DNS resolution problem?

Code:
[root@email /]# cat /etc/hosts
# Do not remove the following line, or various programs
# that require network functionality will fail.
127.0.0.1               localhost.localdomain localhost
192.168.10.37           email.system.com email
Where system.com is just a bogus name for not exposing our host in the forum
DNS and Host files if fine. Is there anyway that i can put the server back up without TLS?

Or do you think because we had a Godaddy cert i need to put teh Goddady cert to put the server back up?

Im running of time to solve this.. should i try to run upgrade for a 6.x version?

heres my system version:
Code:
[zimbra@email ~]$ zmcontrol -v


Release 5.0.21_GA_3151.RHEL4_20091211080331 CentOS4
Reply With Quote
  #12 (permalink)  
Old 01-04-2010, 12:34 PM
Partner (VAR/HSP)
 
Posts: 425
Default

Yes, you should reinstall the certs to be sure. Seems like a problem.
Reply With Quote
  #13 (permalink)  
Old 01-04-2010, 12:37 PM
Intermediate Member
 
Posts: 18
Default

Checking teh update log i found this:

Code:
Mon Jan  4 17:12:22 2010 Setting up CA...
Mon Jan  4 17:12:22 2010 *** Running as root user: /opt/zimbra/openssl/bin/openssl verify -purpose sslserver -CAfile /opt/zimbra/conf/ca/ca.pem /opt/zimbra/conf/ca/ca.pem | egrep ^error 10
Mon Jan  4 17:12:22 2010 *** Running as root user: /opt/zimbra/bin/zmcertmgr createca
Mon Jan  4 17:12:22 2010 done.
Mon Jan  4 17:12:22 2010 Deploying CA to /opt/zimbra/conf/ca ...
Mon Jan  4 17:12:22 2010 *** Running as root user: /opt/zimbra/bin/zmcertmgr deployca -localonly
** Importing CA /opt/zimbra/ssl/zimbra/ca/ca.pem into CACERTS...done.
** Copying CA to /opt/zimbra/conf/ca...done.
Mon Jan  4 17:12:24 2010 done.
Mon Jan  4 17:12:24 2010 *** Running as root user: /opt/zimbra/bin/zmcertmgr verifycrt comm > /dev/null 2>&1
** Verifying /opt/zimbra/ssl/zimbra/commercial/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/opt/zimbra/ssl/zimbra/commercial/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: /opt/zimbra/ssl/zimbra/commercial/commercial.crt: OK
Mon Jan  4 17:12:26 2010 Installing mailboxd SSL certificates...
Mon Jan  4 17:12:26 2010 *** Running as root user: /opt/zimbra/bin/zmcertmgr deploycrt self
** Saving server config key zimbraSSLCertificate...done.
** Saving server config key zimbraSSLPrivateKey...done.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...failed.

XXXXX ERROR: failed to create jetty.pkcs12
unable to load private key

Mon Jan  4 17:12:31 2010 failed.
It seams i already messed up the certs than maybe i should.
Reply With Quote
  #14 (permalink)  
Old 01-04-2010, 01:23 PM
Intermediate Member
 
Posts: 18
Default

I tried to run the Godaddy certs still the same problem

So Iv used the wiki article: Recreating a Self-Signed SSL


Code:
[root@email /]# /opt/zimbra/bin/zmcertmgr verifycrt self
** Verifying /opt/zimbra/ssl/zimbra/server/server.crt against /opt/zimbra/ssl/zimbra/server/server.key
Certificate (/opt/zimbra/ssl/zimbra/server/server.crt) and private key (/opt/zimbra/ssl/zimbra/server/server.key) match.
Valid Certificate: /opt/zimbra/ssl/zimbra/server/server.crt: OK
[root@email /]# /opt/zimbra/bin/zmcertmgr viewdeployedcrt all
::service mta::
notBefore=Jan  4 21:15:22 2010 GMT
notAfter=Jan  4 21:15:22 2011 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=email.moonlight.pt
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=email.moonlight.pt
SubjectAltName=
::service proxy::
notBefore=Jan  4 21:15:22 2010 GMT
notAfter=Jan  4 21:15:22 2011 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=email.moonlight.pt
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=email.moonlight.pt
SubjectAltName=
::service mailboxd::
notBefore=Jan  4 21:15:22 2010 GMT
notAfter=Jan  4 21:15:22 2011 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=email.moonlight.pt
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=email.moonlight.pt
SubjectAltName=
::service ldap::
notBefore=Jan  4 21:15:22 2010 GMT
notAfter=Jan  4 21:15:22 2011 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=email.moonlight.pt
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=email.moonlight.pt
SubjectAltName=
[root@email /]#
And i cant put the server to work. According to the info above iv replaced all certs to a self signed on but i still get the same error what am i doing wrong?

Help! Please
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.