Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-03-2012, 12:52 PM
New Member
 
Posts: 3
Default Problem installing certificate

Hi everyone,

I'm currently trying to install a certificate in a Zimbra installation. The certificate is already working with the Apache2 webserver. The CRS was created with the system's openssl installation.

When doing
Code:
/opt/zimbra/bin/zmcertmgr verifycrt comm private.key public.crt intermediate.crt
I get the following error:
Code:
error 2 at 2 depth lookup:unable to get issuer certificate
That error is produced by the following call:
Code:
/opt/zimbra/openssl/bin/openssl verify -purpose sslserver -CAfile intermediate.crt public.crt
But when doing the same call with the system's openssl installation:
Code:
/usr/bin/openssl verify -purpose sslserver -CAfile intermediate.crt public.crt
I get the following output:
Code:
public.crt: OK
The only difference I could find between the two openssl instances was:

Code:
/usr/bin/openssl version
OpenSSL 0.9.8k 25 Mar 2009

/opt/zimbra/openssl/bin/openssl version
OpenSSL 0.9.8o 01 Jun 2010
So, eventually the question is: how to solve the problem?
Reply With Quote
  #2 (permalink)  
Old 01-03-2012, 02:12 PM
Elite Member
 
Posts: 334
Default

Hi,

Who is the issuer of the certificate? I've installed commercial certificate from Godaddy & RapidSSL without problem.
__________________
Best Regards
---
Masim "Vavai" Sugianto
Vavai Personal Blog
Personal Blog [ID]

Release 7.1.3_GA_3346.SLES11_64_20110930001521 SLES11_64 FOSS edition.
Reply With Quote
  #3 (permalink)  
Old 01-04-2012, 06:07 AM
New Member
 
Posts: 3
Default

Hi vavai,

The issuer is Thawte.
Reply With Quote
  #4 (permalink)  
Old 01-04-2012, 07:04 AM
Elite Member
 
Posts: 334
Default

Have you ever try the suggestion on the following link?

Unable to get issuer certificate - Zimbra :: Wiki

Thawte SSL123 (Did not Use Admin Panel)
__________________
Best Regards
---
Masim "Vavai" Sugianto
Vavai Personal Blog
Personal Blog [ID]

Release 7.1.3_GA_3346.SLES11_64_20110930001521 SLES11_64 FOSS edition.
Reply With Quote
  #5 (permalink)  
Old 01-04-2012, 09:54 AM
New Member
 
Posts: 3
Default

Thank you, concatinating the root certificate to the intermediate one did the trick.

Someone should seriously write that down that the openssl version of Zimbra requires the root certificate as well, and not only the intermediate one.

Last edited by dasprid; 01-04-2012 at 10:13 AM..
Reply With Quote
  #6 (permalink)  
Old 01-04-2012, 03:41 PM
Elite Member
 
Posts: 334
Default

Hi,
Quote:
Originally Posted by dasprid View Post
Thank you, concatinating the root certificate to the intermediate one did the trick.
Glad to hear that you have resolved the problem.


Quote:
Originally Posted by dasprid View Post
Someone should seriously write that down that the openssl version of Zimbra requires the root certificate as well, and not only the intermediate one.
How if you write down your experience on the Zimbra wiki? Or maybe write down your experience here so I can help to write your tips on Zimbra wiki.
__________________
Best Regards
---
Masim "Vavai" Sugianto
Vavai Personal Blog
Personal Blog [ID]

Release 7.1.3_GA_3346.SLES11_64_20110930001521 SLES11_64 FOSS edition.
Reply With Quote
  #7 (permalink)  
Old 01-10-2012, 01:17 AM
Starter Member
 
Posts: 1
Default

Quote:
Originally Posted by dasprid View Post
Hi everyone,

I'm currently trying to install a certificate in a Zimbra installation. The certificate is already working with the Apache2 webserver. The CRS was created with the system's openssl installation.

When doing
Code:
/opt/zimbra/bin/zmcertmgr verifycrt comm private.key public.crt intermediate.crt
I get the following error:
Code:
error 2 at 2 depth lookup:unable to get issuer certificate
That error is produced by the following call:
Code:
/opt/zimbra/openssl/bin/openssl verify -purpose sslserver -CAfile intermediate.crt public.crt
But when doing the same call with the system's openssl installation:
Code:
/usr/bin/openssl verify -purpose sslserver -CAfile intermediate.crt public.crt
I get the following output:
Code:
public.crt: OK
The only difference I could find between the two openssl instances was:

Code:
/usr/bin/openssl version
OpenSSL 0.9.8k 25 Mar 2009

/opt/zimbra/openssl/bin/openssl version
OpenSSL 0.9.8o 01 Jun 2010
So, eventually the question is: how to solve the problem?

Thank you, concatinating the root certificate to the intermediate one did the trick.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.