Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-02-2010, 02:53 PM
Elite Member
 
Posts: 469
Default Help needed to regenerate SLL cert

I have installed 6.0.4 FOSS on Centos 5.3

When installing I named the server zimbra.domain.ctry, and it generated an ssl cert based on that name.

However, our public email hostname is mail.domain.ctry - so the name of the cert does not match, and briefcase documents are not accessible externally.

I have since set the ZimbraPublicServiceHostname and ZimbraPublicServiceProtocol to the appropriate values so that briefcase works correctly. However, I would also like to set the SSL cert straightened out.

I have tried to generate a new SSL cert both through the Admin GUI, and with the CLI tool, but no matter what I do I keep getting a cert with the Subject zimbra.domain.ctry

It ignores the O, and OU settings I input, and ignores the AlternativeSubjects I specify too.

The articles I have been able to find on the wiki all refer to 4.5 and 5.0 - so has something changed in 6.0 ?

Can anyone walk me through the steps I need to take as I am obviously missing something.

Thanks
Reply With Quote
  #2 (permalink)  
Old 02-02-2010, 11:05 PM
Zimbra Consultant & Moderator
 
Posts: 20,317
Default

Why don't you just change the server name with ZmSetServerName to the new name you require?
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 02-02-2010, 11:12 PM
Moderator
 
Posts: 7,929
Default

Additionally if your internal server name is different to how it is seen externally your emails may get tagged as SPAM.
__________________
Reply With Quote
  #4 (permalink)  
Old 02-03-2010, 01:47 AM
Elite Member
 
Posts: 469
Default

To date I have never had an issue with the server name being different from the external name - with zimbra or either of our previous email servers.

However, if the best way forward is to rename the server, I am willing to do so.

I am confused though as to how this will solve my current problem - which is that I cannot get a new ssl cert generated with any name other than zimbra.company.ctry

Is the ssl cert generation looking at the hostname somewhere under the covers, and ignoring what I type ?

If it is not, I am going to be in an even more screwed up state - where everything internally and externally points to mail.domain.ctry - but the ssl cert is different from that.
Reply With Quote
  #5 (permalink)  
Old 02-04-2010, 02:22 PM
Elite Member
 
Posts: 469
Default

I finally got this to work. But, I still have some questions/observations.

I followed the WIKI article Administration Console and CLI Certificate Tools - Zimbra :: Wiki

I followed the example "Single-Node Self-Signed Certificate"

It seems to me that there is a step missing between Generating an new CA, and generating a certificate signed by it. Unless I ran the command

Code:
zmcertmgr deployca
I could not get any of my custom changes in the CA to take. Is this correct ?

Secondly it appears to me that the command

Code:
createcsr (self|comm) [-new] [-subject subject] [-subjectAltNames "host1,host2"] 

Note: Angle brackets changed to parentheses for display purposes
The angle brackets caused the parameter to disappear from the post ?
is asking for one required parameter, self or comm, and up to 3 optional parameters. Am I misunderstanding what the (self|comm) means ?

I found that if I included the "self" parameter my command failed, and did nothing. Removing it allowed me to generate a certificate signing request.

I would appreciate your feedback.

Last edited by liverpoolfcfan; 02-04-2010 at 02:29 PM.. Reason: Change angle brackets to partntheses for display purposes
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.