Installing SSL Certificate on Zimbra


Using the CLI
·         1. Get the certificate from ssl authority in crt/txt format, or sometimes like a zip file.
·         2. Place the Certificate on your Zimbra mailbox server. You should receive below files:
o    Root.crt
o    Intermediate.crt
o    My_Domain_com.crt files
Note the root and intermediate files may have different names depends of the SSL Certificate, like DigiCert etc.
Note 2 all the below commands should be run as zimbra user starting ZCS 8.7 and above, and as a root user in ZCS 8.6 and below.
·         3. Cat the CA certs to form a single CA certificate chain file
 cat Root.crt Intermediate.crt > /tmp/commercial_ca.crt
·         4. Place the SSL certificate in /tmp/commercial.crt.
 cp my_domain_com.crt /tmp/commercial.crt
·         5. Copy private key file (which is generate at a time of CSR generation) on below path and rename it  commercial.key  .
/opt/Zimbra/ssl/Zimbra/commercial/commercial.key
·         6. Check that your SSL certificate, your private key and the Intermediate CA are OK, this step is important and you should not continue if you receive an error here:
/opt/zimbra/bin/zmcertmgr verifycrt comm /opt/zimbra/ssl/zimbra/commercial/commercial.key /tmp/commercial.crt /tmp/commercial_ca.crt
** Verifying /tmp/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: /tmp/commercial.crt: OK
·         7. Deploy the commercial certificate with zmcertmgr as the Zimbra user.
/opt/zimbra/bin/zmcertmgr deploycrt comm /tmp/commercial.crt /tmp/commercial_ca.crt
** Verifying /tmp/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: /tmp/commercial.crt: OK
** Copying /tmp/commercial.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Appending ca chain /tmp/commercial_ca.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Importing certificate /opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt to CACERTS as zcs-user-commercial_ca...done.
** NOTE: mailboxd must be restarted in order to use the imported certificate.
** Saving server config key zimbraSSLCertificate...done.
** Saving server config key zimbraSSLPrivateKey...done.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to /opt/zimbra/conf/ca...done.
·         8. Restart the Zimbra Services
zmcontrol restart


No comments:

Post a Comment