{"id":573,"date":"2019-01-17T13:17:14","date_gmt":"2019-01-17T12:17:14","guid":{"rendered":"http:\/\/blog.nosland.com\/?p=573"},"modified":"2019-01-17T13:17:17","modified_gmt":"2019-01-17T12:17:17","slug":"ssl-zimbra","status":"publish","type":"post","link":"http:\/\/blog.nosland.com\/?p=573","title":{"rendered":"SSL Zimbra"},"content":{"rendered":"\n<p class=\"has-text-color has-background has-very-dark-gray-color has-pale-cyan-blue-background-color\">Cas SSL chez COMODO via namecheap<\/p>\n\n\n\n<p>On se connecte sur l&rsquo;interface d&rsquo;admin web de Zimbra <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"1912\" height=\"396\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-404.png\" alt=\"\" class=\"wp-image-574\"\/><figcaption>Dans le menu de gauche on clique sur la rubrique \u00ab\u00a0Configurer\u00a0\u00bb<br><br><\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"502\" height=\"307\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-405.png\" alt=\"\" class=\"wp-image-575\"\/><figcaption>On clique sur le sous menu \u00ab\u00a0Certificats\u00a0\u00bb<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"195\" height=\"131\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-406.png\" alt=\"\" class=\"wp-image-576\"\/><figcaption>En haut \u00e0 droite, ouvrir le menu de configuration. <br>Choisir Installer le certificat<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"656\" height=\"375\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-407.png\" alt=\"\" class=\"wp-image-577\"\/><figcaption>Choisir son serveur dans le menu d\u00e9roulant<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"664\" height=\"391\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-408.png\" alt=\"\" class=\"wp-image-578\"\/><figcaption>Cocher \u00ab\u00a0G\u00e9n\u00e9rer la demande de certificat (CSR) aupr\u00e8s de l&rsquo;\u00e9metteur commercial.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"676\" height=\"403\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-409.png\" alt=\"\" class=\"wp-image-579\"\/><figcaption>V\u00e9rifier les infos pour la CSR<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"672\" height=\"396\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-410.png\" alt=\"\" class=\"wp-image-580\"\/><figcaption>Cliquer sur \u00ab\u00a0T\u00e9l\u00e9charger la demande CSR g\u00e9n\u00e9r\u00e9e\u00a0\u00bb<\/figcaption><\/figure>\n\n\n\n<p>Vous rendre sur le site de votre fournisseur de SSL favori et faites une demande de SSL \u00e0 partir de votre CSR<\/p>\n\n\n\n<p>Votre fournisseur vous renverra au moins deux fichiers dans un ZIP : le certificat serveur sous la forme mon_nom_de_domaine.crt et mon_nom_de_domaine.ca-bundle <br>Pour l&rsquo;installation de Zimbra \u00e7a ne suffira pas. Vous devez donc demander \u00e0 votre fournisseur de vous faire parvenir 3 fichiers : <em>AddTrustExternalCARoot.crt<br>COMODORSAAddTrustCA.crt<br>COMODORSADomainValidationSecureServerCA.crt<\/em><\/p>\n\n\n\n<p>En fonction du type de SSL que vous avez achet\u00e9 et aussi en fonction du fournisseur les noms peuvent diff\u00e9rer. <\/p>\n\n\n\n<p>Transf\u00e9rer les 4 fichiers sur votre serveur. puis connectez vous en SSH dessus. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"705\" height=\"69\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-411.png\" alt=\"\" class=\"wp-image-581\"\/><figcaption>Afin d&rsquo;utiliser ces certificats sur Zimbra nous allons les transformer. <\/figcaption><\/figure>\n\n\n\n<p>lancer les commandes suivantes : <\/p>\n\n\n\n<p style=\"color:#faf700\" class=\"has-text-color has-background has-small-font-size has-very-dark-gray-background-color\">cp anakin_nosland_com.crt commercial.crt<br>cat AddTrustExternalCARoot.crt COMODORSAAddTrustCA.crt COMODORSADomainValidationSecureServerCA.crt > commercial_ca.crt<\/p>\n\n\n\n<p>Vous devriez obtenir : <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" width=\"806\" height=\"97\" src=\"http:\/\/blog.nosland.com\/wp-content\/uploads\/2019\/01\/image-412.png\" alt=\"\" class=\"wp-image-584\"\/><\/figure>\n\n\n\n<p>Se placer sous l&rsquo;utilisateur Zimbra (su zimbra)<br>nous allons tester les fichiers avant de les int\u00e9grer<\/p>\n\n\n\n<p class=\"has-text-color has-background has-small-font-size has-vivid-green-cyan-color has-very-dark-gray-background-color\">\/opt\/zimbra\/bin\/zmcertmgr verifycrt comm \/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.key comercial.crt commercial_ca.crt<\/p>\n\n\n\n<p>Vous devriez avoir des r\u00e9ponses comme-ci : <\/p>\n\n\n\n<p class=\"has-text-color has-background has-small-font-size has-vivid-green-cyan-color has-very-dark-gray-background-color\">Certificate &lsquo;commercial.crt&rsquo; and private key &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.key&rsquo; match.<br> ** Verifying &lsquo;commercial.crt&rsquo; against &lsquo;commercial_ca.crt&rsquo;<br> Valid certificate chain: commercial.crt: OK<\/p>\n\n\n\n<p>Si c&rsquo;est OK il suffit de d\u00e9ployer <\/p>\n\n\n\n<p class=\"has-text-color has-background has-small-font-size has-vivid-green-cyan-color has-very-dark-gray-background-color\">zmcertmgr deploycrt comm commercial.crt commercial_ca.crt<br> ** Verifying &lsquo;commercial.crt&rsquo; against &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.key&rsquo;<br> Certificate &lsquo;commercial.crt&rsquo; and private key &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.key&rsquo; match.<br> ** Verifying &lsquo;commercial.crt&rsquo; against &lsquo;commercial_ca.crt&rsquo;<br> Valid certificate chain: commercial.crt: OK<br> ** Copying &lsquo;commercial.crt&rsquo; to &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.crt&rsquo;<br> ** Copying &lsquo;commercial_ca.crt&rsquo; to &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial_ca.crt&rsquo;<br> ** Appending ca chain &lsquo;commercial_ca.crt&rsquo; to &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.crt&rsquo;<br> ** Importing cert &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial_ca.crt&rsquo; as &lsquo;zcs-user-commercial_ca&rsquo; into cacerts &lsquo;\/opt\/zimbra\/common\/lib\/jvm\/java\/jre\/lib\/security\/cacerts&rsquo;<br> ** NOTE: restart mailboxd to use the imported certificate.<br> ** Saving config key &lsquo;zimbraSSLCertificate&rsquo; via zmprov modifyServer anakin.nosland.com\u2026ok<br> ** Saving config key &lsquo;zimbraSSLPrivateKey&rsquo; via zmprov modifyServer anakin.nosland.com\u2026ok<br> ** Installing imapd certificate &lsquo;\/opt\/zimbra\/conf\/imapd.crt&rsquo; and key &lsquo;\/opt\/zimbra\/conf\/imapd.key&rsquo;<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.crt&rsquo; to &lsquo;\/opt\/zimbra\/conf\/imapd.crt&rsquo;<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.key&rsquo; to &lsquo;\/opt\/zimbra\/conf\/imapd.key&rsquo;<br> ** Creating file &lsquo;\/opt\/zimbra\/ssl\/zimbra\/jetty.pkcs12&rsquo;<br> ** Creating keystore &lsquo;\/opt\/zimbra\/conf\/imapd.keystore&rsquo;<br> ** Installing ldap certificate &lsquo;\/opt\/zimbra\/conf\/slapd.crt&rsquo; and key &lsquo;\/opt\/zimbra\/conf\/slapd.key&rsquo;<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.crt&rsquo; to &lsquo;\/opt\/zimbra\/conf\/slapd.crt&rsquo;<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.key&rsquo; to &lsquo;\/opt\/zimbra\/conf\/slapd.key&rsquo;<br> ** Creating file &lsquo;\/opt\/zimbra\/ssl\/zimbra\/jetty.pkcs12&rsquo;<br> ** Creating keystore &lsquo;\/opt\/zimbra\/mailboxd\/etc\/keystore&rsquo;<br> ** Installing mta certificate &lsquo;\/opt\/zimbra\/conf\/smtpd.crt&rsquo; and key &lsquo;\/opt\/zimbra\/conf\/smtpd.key&rsquo;<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.crt&rsquo; to &lsquo;\/opt\/zimbra\/conf\/smtpd.crt&rsquo;<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.key&rsquo; to &lsquo;\/opt\/zimbra\/conf\/smtpd.key&rsquo;<br> ** Installing proxy certificate &lsquo;\/opt\/zimbra\/conf\/nginx.crt&rsquo; and key &lsquo;\/opt\/zimbra\/conf\/nginx.key&rsquo;<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.crt&rsquo; to &lsquo;\/opt\/zimbra\/conf\/nginx.crt&rsquo;<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.key&rsquo; to &lsquo;\/opt\/zimbra\/conf\/nginx.key&rsquo;<br> ** NOTE: restart services to use the new certificates.<br> ** Cleaning up 9 files from &lsquo;\/opt\/zimbra\/conf\/ca&rsquo;<br> ** Removing \/opt\/zimbra\/conf\/ca\/d6325660.0<br> ** Removing \/opt\/zimbra\/conf\/ca\/commercial_ca_2.crt<br> ** Removing \/opt\/zimbra\/conf\/ca\/commercial_ca_3.crt<br> ** Removing \/opt\/zimbra\/conf\/ca\/ca.key<br> ** Removing \/opt\/zimbra\/conf\/ca\/ca.pem<br> ** Removing \/opt\/zimbra\/conf\/ca\/157753a5.0<br> ** Removing \/opt\/zimbra\/conf\/ca\/8d28ae65.0<br> ** Removing \/opt\/zimbra\/conf\/ca\/6d667efc.0<br> ** Removing \/opt\/zimbra\/conf\/ca\/commercial_ca_1.crt<br> ** Copying CA to \/opt\/zimbra\/conf\/ca<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/ca\/ca.key&rsquo; to &lsquo;\/opt\/zimbra\/conf\/ca\/ca.key&rsquo;<br> ** Copying &lsquo;\/opt\/zimbra\/ssl\/zimbra\/ca\/ca.pem&rsquo; to &lsquo;\/opt\/zimbra\/conf\/ca\/ca.pem&rsquo;<br> ** Creating CA hash symlink &lsquo;6d667efc.0&rsquo; -> &lsquo;ca.pem&rsquo;<br> ** Creating \/opt\/zimbra\/conf\/ca\/commercial_ca_1.crt<br> ** Creating CA hash symlink &lsquo;157753a5.0&rsquo; -> &lsquo;commercial_ca_1.crt&rsquo;<br> ** Creating \/opt\/zimbra\/conf\/ca\/commercial_ca_2.crt<br> ** Creating CA hash symlink &lsquo;fc5a8f99.0&rsquo; -> &lsquo;commercial_ca_2.crt&rsquo;<br> ** Creating \/opt\/zimbra\/conf\/ca\/commercial_ca_3.crt<br> ** Creating CA hash symlink &rsquo;65ff7287.0&prime; -> &lsquo;commercial_ca_3.crt&rsquo;<\/p>\n\n\n\n<p>Une fois fait, il suffit de relancer Zimbra : \u00ab\u00a0zmcontrol restart\u00a0\u00bb<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cas SSL chez COMODO via namecheap On se connecte sur l&rsquo;interface d&rsquo;admin web de Zimbra Vous rendre sur le site&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[],"_links":{"self":[{"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/posts\/573"}],"collection":[{"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=573"}],"version-history":[{"count":4,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/posts\/573\/revisions"}],"predecessor-version":[{"id":586,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=\/wp\/v2\/posts\/573\/revisions\/586"}],"wp:attachment":[{"href":"http:\/\/blog.nosland.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=573"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.nosland.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}