Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Mobility > Zimbra Mobile

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-01-2012, 05:35 AM
Active Member
 
Posts: 26
Default installed a new ssl cert but activesync won't use it

I installed a new SSL cert (because the old one expired.) All the standard zimbra services work fine, and all use the new cert, but activesync continues to use the old one. Of course, now that its expired, devices refuse to connect.

What do I need to do to update the SSL cert for activesync?

Andy
__________________
---
Release 7.1.1_GA_3196.UBUNTU8_64
UBUNTU8_64 NETWORK edition.
Reply With Quote
  #2 (permalink)  
Old 02-01-2012, 06:18 AM
Advanced Member
 
Posts: 213
Default

Dunno...
- does the sync.log show anything about this?
- What is the output of
/opt/zimbra/bin/zmcertmgr viewdeployedcrt mailboxd
- typically the mailboxd (which I think handles activesync as well?? could be wrong) stores its' keystore at /opt.zimbra/conf/keystore... however, I have seen where it can be used/located at /opt/zimbra/mailboxd/etc/keystore. See if you have that, maybe even compare?
Reply With Quote
  #3 (permalink)  
Old 02-01-2012, 01:54 PM
Active Member
 
Posts: 26
Default

Hey thanks Greg :-)

Turns out, /opt/zimbra/conf/domaincerts did have the old crt/key files in it. I've backed them up and replaced them with the new stuff. Good thinking.

Andy
__________________
---
Release 7.1.1_GA_3196.UBUNTU8_64
UBUNTU8_64 NETWORK edition.
Reply With Quote
  #4 (permalink)  
Old 02-01-2012, 02:55 PM
Active Member
 
Posts: 26
Default

So, /opt/zimbra/bin/zmcertmgr viewdeployedcrt returns the correct certs, and it doesn't make any reference to the cert that activesync is using.

Still stumped.
__________________
---
Release 7.1.1_GA_3196.UBUNTU8_64
UBUNTU8_64 NETWORK edition.
Reply With Quote
  #5 (permalink)  
Old 02-02-2012, 06:08 AM
Active Member
 
Posts: 26
Default

We solved this problem. Here is how:

Our next step was to try another device. I had a colleague with an android device try to add an activesync account. He got an error, but in this case his device showed the proper (new) certificate, so we suspected that the problem was device related. Further reading suggested that the primary domain on the certificate must match the access URL (which in this case it did not - a wildcard cert has *.domain.com as its primary name).

We bought a dedicated, for the purpose, single domain certificate, deployed that, and the problem went away.

I suspected that the device was caching the old certificate, but I couldn't figure out why it would use it. Now, knowing that it didn't like the new one, I can almost understand. Bottom line here is that the wildcard certificate simply would not work for activesync.
__________________
---
Release 7.1.1_GA_3196.UBUNTU8_64
UBUNTU8_64 NETWORK edition.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.