Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-08-2009, 10:15 AM
Starter Member
 
Posts: 2
Exclamation persistent errors comodo ssl certificate installation

Since our certificate expired, I have been unable to install a new Comodo certificate.

It is unclear to me, what are the exact steps to clean everything and start from scratch.

The main steps I am taking are to generate a new CSR via the admin webconsole and submit that to Comodo, then to either via the commandline concatenate a bundle and verify the certificate - which generates an error - or install the certificate via the admin web console - which generates an error, also.

The errors that are being generated are:
(admin web console
Your certificate was not installed due to the error : system failure: XXXXX ERROR: Invalid Certificate Chain:

and:

root@mail:/tmp# /opt/zimbra/bin/zmcertmgr verifycrt comm /opt/zimbra/ssl/zimbra/ commercial/commercial.key /tmp/manascmail_com.crt
** Verifying /tmp/manascmail_com.crt against /opt/zimbra/ssl/zimbra/commercial/c ommercial.key
Certificate (/tmp/manascmail_com.crt) and private key (/opt/zimbra/ssl/zimbra/co mmercial/commercial.key) match.
Error loading file /opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt
19555:error:02001002:system library:fopen:No such file or directory:bss_file.c:1 26:fopen('/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt','r')
19555:error:2006D080:BIO routines:BIO_new_file:no such file:bss_file.c:129:
19555:error:0B084002:x509 certificate routines:X509_load_cert_crl_file:system li b:by_file.c:274:

It seems obvious that the second error explains the invalid chain error, but I don't understand how I can generate a commercial_ca.crt.

We are using Zimbra Release 6.0.1_GA_1816.UBUNTU8_64 UBUNTU8_64 FOSS edition.

The new certificate has a 5 year validity.
Zimbra was upgraded since the last certificate installation.


Thanks for any input on this matter :-)
Reply With Quote
  #2 (permalink)  
Old 12-10-2009, 10:23 AM
Starter Member
 
Posts: 2
Default

Ok, I copied the commercial_ca.crt to the correct dir

Now I am (back) at an error I had in earlier attemps of installing the certificate:

root@mail:/tmp# cp CARoot.crt /opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt
root@mail:/tmp# /opt/zimbra/bin/zmcertmgr verifycrt comm /opt/zimbra/ssl/zimbra/commercial/commercial.key /tmp/manascmail_com.crt
** Verifying /tmp/manascmail_com.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/manascmail_com.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
XXXXX ERROR: Invalid Certificate: /tmp/manascmail_com.crt: /C=CA/ST=Alberta/L=Edmonton/O=Manasc Isaac Architects Ltd/OU=IT/OU=Comodo InstantSSL/CN=manascmail.com

error 20 at 0 depth lookup:unable to get local issuer certificate

The article "Unable to get issuer certificate" is pointing to this article:
Cryptography Tutorials - Herong's Tutorial Notes - OpenSSL - Certification Path and Validation which is an awesome read, but does not give me clear instructions on how to fix it.


Any help still appreciated :-)
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.