Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-11-2011, 05:21 AM
Junior Member
 
Posts: 5
Unhappy Doubts about the commercial SSL certificate installation

Guys, sorry for my bad Inglês, is not my native language

I have today an e-mail server Postfix That runs and use a commercial certificate of Thawte. This certificate is used for connections via Webmail, IMAP and POP. and works very well.

I am migrating this server e-mail to the Zimbra Open Source and 7 am HAVING some doubts about the SSL certificates.

Can I reuse my old certificates Which Were used in the old server? If yes, is there any process I have to take?

If I Can not take my old certificate, then I must generate a new one. When I generate the new certificate in Thawte, I generate the certificate for the domain mail.xxxxxx.com

Here it is my greatest doubts. When I ride my server, the name of my server has to Be Exactly equal to the domain name in the register in Thawte? or Can I use any name for the server? and then generate a certificate in the Thawte for mail.xxxx.com domain?

Thank you for everyone's help.
Reply With Quote
  #2 (permalink)  
Old 02-11-2011, 05:56 AM
Active Member
 
Posts: 34
Default

Quote:
Originally Posted by clark kent View Post
Can I reuse my old certificates Which Were used in the old server? If yes, is there any process I have to take?
You can reuse your old certificate. You need to copy it from the old server and install it to the new server. See zimbra wiki page about installing commercial certificates.

Quote:
Originally Posted by clark kent View Post
If I Can not take my old certificate, then I must generate a new one. When I generate the new certificate in Thawte, I generate the certificate for the domain mail.xxxxxx.com

Here it is my greatest doubts. When I ride my server, the name of my server has to Be Exactly equal to the domain name in the register in Thawte? or Can I use any name for the server? and then generate a certificate in the Thawte for mail.xxxx.com domain?

Thank you for everyone's help.
If you decide to reuse your old certificate, your new servers public hostname must exactly match the one you registered the old certificate with.

If you need to change the public hostname of the server, you need to register new certificate to match the new name.
Reply With Quote
  #3 (permalink)  
Old 02-11-2011, 08:01 AM
Junior Member
 
Posts: 5
Default

Hello,

Thank you for your quick response.

Well, I decided to run some tests, and i tried to generate the CSR file to send to Thawte. i can generate the file perteitamente by WebGUI, I put all the necessary information, but when Thawte will check the file CSR, tells me that the country code is not included. the exact error is:

"The CSR must include the Country Code"

At the time of generation of Certificate I really put the country code.

Someone has gone through this kind of problem?
Reply With Quote
  #4 (permalink)  
Old 02-11-2011, 10:32 AM
Active Member
 
Posts: 34
Default

This sounds like a typo while entering data or a bug in webgui to me.
Country code is two letter country identificator, for example, DE, FR, ES, FI etc.

The CSR generator should ask for the country code.
Reply With Quote
  #5 (permalink)  
Old 02-11-2011, 10:49 AM
Junior Member
 
Posts: 5
Default

I agree with you, in the WebGUI I insert this information as requested. and yet the Thwate returns me this error.

I have three suspects for this,

- The Thwate should not recognize as the CSR format (unlikely)

- The Version 7.0 because it is new, deals of the generation of CSR file in a different way of default (also unlikely)

- The WebGUI tool has some sort of bug, which generates the CSR, he does not read correctly the information.

I will try to generate the same key using the tool zmcertmgr and i will post again.
Reply With Quote
  #6 (permalink)  
Old 02-11-2011, 11:07 AM
Active Member
 
Posts: 34
Default

Quote:
Originally Posted by clark kent View Post
- The Thwate should not recognize as the CSR format (unlikely)
Very unlikely, as they have CSR parser which checks if the file you send them is valid, and gives the error.


Quote:
Originally Posted by clark kent View Post
- The Version 7.0 because it is new, deals of the generation of CSR file in a different way of default (also unlikely)
Was there a CSR creator in 6.x webgui?

Quote:
Originally Posted by clark kent View Post
- The WebGUI tool has some sort of bug, which generates the CSR, he does not read correctly the information.
This is what I'd assume aswell.

Quote:
Originally Posted by clark kent View Post
I will try to generate the same key using the tool zmcertmgr and i will post again.
Using zmcertmgr from command line, you should end up with valid Certificate Signing Request.
Reply With Quote
  #7 (permalink)  
Old 02-14-2011, 10:26 AM
Junior Member
 
Posts: 5
Default

Good news.

I formatted my server and i installed Zimbra Open 6.0. I generated the certificate CSR by WebGUI normally, just as i tryed in Zimbra 7.0 and the Thawte recognized perfectly my certificate

Really believe it's a Bug in WebGUI tool, I will pass this information to the staff of Zimbra to investigate better what may be happening.


Thank you for your help.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.