Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 10-16-2009, 05:16 PM
Junior Member
 
Posts: 7
Default Installing existing ssl certificates

Hi, I am a newbie when it comes to unix based OS's, zimbra and ssl and I have recently been given the assignment of setting up a zimbra server on ubuntu 8.04 using already purchased/ signed certificates from godaddy.com. I have the server up and running and the few remaining tasks include installing the ssl certificates I was provided. How do I go about this?
Reply With Quote
  #2 (permalink)  
Old 10-17-2009, 12:23 AM
Moderator
 
Posts: 7,929
Default

Welcome to the forums

Installing a GoDaddy Commercial Certificate - Zimbra :: Wiki
__________________
Reply With Quote
  #3 (permalink)  
Old 10-19-2009, 04:00 PM
Junior Member
 
Posts: 7
Default

Installation Prequisites

This article is written for installations that meet the following prerequisites.

* This is a new certificate.
* You generated the CSR via the Administration Console.
* You sent the CSR to get it signed
* Download the following files from https://certs.godaddy.com/Repository.go
* The /opt/zimbra/ssl/zimbra/commercial has two files:
o commercial.key
o commercial.csr

If your certificate does not meet the above prerequisites, the following installation instructions may not work.
---------------------------------------------------------------------------------
ZCS Version: Release 6.0.1_GA_1816.UBUNTU8_64 UBUNTU8_64 FOSS edition

The certs I was provided with were not generated with the administration console, I was told they were signed. These are not new certs. Is it possible to install these ssl certs even though they do not meet that criteria?

Last edited by jld1989; 10-19-2009 at 05:02 PM..
Reply With Quote
  #4 (permalink)  
Old 10-20-2009, 04:54 PM
Junior Member
 
Posts: 7
Default

I found a way to deploy the certs however it is causing an "Unable to determine enabled services from ldap. Enabled services read from cache. Service list may be inaccurate." error. I was provided with a matching .key and .crt file for the company domain as well as a gd_bundle.crt. The process I am using to deploy these certs is as follows. I first generate a commercial.csr and commercial.key file from the administration console. I then replace the commercial.key file with the key I was provided with, I rename it to commercial.key and adjust permission to match with original commercial.key file. I rename the gd_bundle.crt to commercial_ca.crt and rename the domains cert to commercial.crt and verify the certs with /opt/zimbra/bin/zmcertmgr verifycrt comm /opt/zimbra/ssl/zimbra/commercial/commercial.key ./commercial.crt ./commercial_ca.crt It is successful. I then proceed to deploy the certs using the /opt/zimbra/bin/zmcertmgr deploycrt comm ./commercial.crt. /commercial_ca.crt command and that to is successful.
Following that I restart zimbra and I am then presented with this.

Starting ldap...Done.
Unable to determine enabled services from ldap.
Enabled services read from cache. Service list may be inaccurate.
Starting logger...Done.
Starting mailbox...Done.
Starting memcached...Done.
Starting antispam...Done.
Starting antivirus...Done.
Starting snmp...Done.
Starting spell...Done.
Starting mta...Done.
Starting stats...Done.
I am unable to access the administration console and the server is not functional in the least. Any help would be much appreciated.

Oh, the cert I was provided with is a wild card cert.

Last edited by jld1989; 10-21-2009 at 02:28 PM..
Reply With Quote
  #5 (permalink)  
Old 11-10-2009, 12:49 PM
Intermediate Member
 
Posts: 17
Default

Did you ever get your wildcard installed and working? I'd like to do the same but, I'm afraid I might break my install like yours is. Just wondering if you found a workaround. I extra cautious since I have multiple servers and breaking LDAP would break their functionality.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.