Certificate chain for 8.71 mailbox server on private LAN with MTA on DMZ

Ask questions about your setup or get help installing ZCS server (ZD section below).
Post Reply
mskirl
Posts: 2
Joined: Wed Feb 15, 2017 2:58 pm

Certificate chain for 8.71 mailbox server on private LAN with MTA on DMZ

Post by mskirl »

Hi all

would like to send encrypted and/or signed email from 8.71 Zimbra mailbox server (on Ubuntu 14.04), protected on a private LAN without internet access.
Another server (same versions) is doing MTA, located in the DMZ, able to access the internet.
Zimbra clients will connect to the mailbox server via vpn connect to the private LAN.
Purchased a public gold certificate from a public provider.

I understand, that the Zimbra mailbox server should have a trusted certificate (I guess, not self signed in order to do encrypted and signed emails). But is it possible to use the Zimbra MTA as an intermediate/proxy/cross chain/whatever-trusting instance, so that the certificates of the mailbox server and the public certificates can interact somehow ?

All the best
Miguel
User avatar
vavai
Advanced member
Advanced member
Posts: 174
Joined: Thu Nov 14, 2013 2:41 pm
Location: Indonesia
ZCS/ZD Version: 0
Contact:

Re: Certificate chain for 8.71 mailbox server on private LAN with MTA on DMZ

Post by vavai »

Hi,
mskirl wrote:Hi all

would like to send encrypted and/or signed email from 8.71 Zimbra mailbox server (on Ubuntu 14.04), protected on a private LAN without internet access.
Another server (same versions) is doing MTA, located in the DMZ, able to access the internet.
Zimbra clients will connect to the mailbox server via vpn connect to the private LAN.
Purchased a public gold certificate from a public provider.

I understand, that the Zimbra mailbox server should have a trusted certificate (I guess, not self signed in order to do encrypted and signed emails). But is it possible to use the Zimbra MTA as an intermediate/proxy/cross chain/whatever-trusting instance, so that the certificates of the mailbox server and the public certificates can interact somehow ?

All the best
Miguel
Actually I'm a little bit confused with the terms "encrypted" and "signed", as encrypted are usually refer to S/MIME or PGP and signed are related to DKIM :D but if your case are on SSL certificate, then you can get the wildcard SSL certificate, install it on all server (even if it is on private LAN) and then all of them communicate each other and to the outside with TLS connection as well.
Post Reply